Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2024-22425MEDIUMDell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attaEPSS 0.5%CVE-2024-32868MEDIUMZITADEL's Improper Lockout Mechanism Leads to MFA BypassEPSS 0.5%CVE-2025-64310CRITICALEPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrativEPSS 0.5%CVE-2025-42600HIGHBrute Force Attack Vulnerability in Meon KYC solutionsEPSS 0.5%CVE-2026-6947HIGHD-Link|DWM-222W USB Wi-Fi Adapter - Brute-Force Protection BypassEPSS 0.5%CVE-2026-47203LOWAuthelia Missing Username Canonicalization in Basic Auth (LDAP)EPSS 0.5%CVE-2024-3102MEDIUMJSON Injection in mintplex-labs/anything-llmEPSS 0.5%CVE-2025-1740CRITICALAuthentication Bypass in Akinsoft's MyRezztaEPSS 0.5%CVE-2026-73056CRITICALSiYuan kernel before 3.7.4 Unthrottled Brute-Force via API TokenEPSS 0.4%CVE-2025-69615CRITICALIncorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction rEPSS 0.4%CVE-2026-3329HIGHNexus Repository Manager - Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2023-41270LOWSamsung Smart TV UE40D7000 WPS DoS attackEPSS 0.4%CVE-2024-39873HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly imEPSS 0.4%CVE-2024-41682MEDIUMA vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce restricEPSS 0.4%CVE-2025-67853HIGHMoodle: moodle: brute-force facilitation due to missing rate limiting in confirmation email serviceEPSS 0.4%CVE-2023-32251LOWKernel: ksmbd brute force delay bypass via asynchronous requestsEPSS 0.4%CVE-2022-34389LOW Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentialEPSS 0.4%CVE-2025-2417HIGHOTP Bypass in Akinsoft's e-MutabakatEPSS 0.4%CVE-2026-6223CRITICALOTP Bypass in Bahçelievler Muncipality's BiHayat AppEPSS 0.4%CVE-2025-2411HIGHOTP Bypass in Akinsoft's TaskPanoEPSS 0.4%