Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2026-26227MEDIUMVLC for Android < 3.7.0 Remote Access OTP Authentication BypassEPSS 0.3%CVE-2026-15079MEDIUMLogin Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070EPSS 0.3%CVE-2025-59113MEDIUMBruteforce Protection Bypass in Windu CMSEPSS 0.3%CVE-2026-25577HIGHEmmett has an Unhandled CookieError Exception Causing Denial of ServiceEPSS 0.3%CVE-2025-10161HIGHAuthentication Bypass in Turkguven's PerfektiveEPSS 0.3%CVE-2026-85237HIGHMissing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication BypassEPSS 0.3%CVE-2026-2402MEDIUMCWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the usEPSS 0.3%CVE-2025-65427MEDIUMAn issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to EPSS 0.3%CVE-2026-34505MEDIUMOpenClaw < 2026.3.12 - Webhook Rate Limiting Bypass via Pre-Authentication Secret ValidationEPSS 0.3%CVE-2025-28172MEDIUMGrandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker cEPSS 0.3%CVE-2026-33879LOWFLIP doesn't have rate limiting or brute-force protection on loginEPSS 0.3%CVE-2026-16347HIGHImproper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted RouterEPSS 0.3%CVE-2025-3129MEDIUMAccess code - Moderately critical - Access bypass - SA-CONTRIB-2025-028EPSS 0.3%CVE-2025-47951MEDIUMWeblate lacks rate limiting when verifying second factorEPSS 0.3%CVE-2026-82644HIGHWWBN AVideo Brute-force Rate Limiting Bypass via Missing User-AgentEPSS 0.3%CVE-2026-27981HIGHHomeBox has an Auth Rate Limit Bypass via IP SpoofingEPSS 0.3%CVE-2026-27801MEDIUMVaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit EnforcementEPSS 0.3%CVE-2026-41213MEDIUM@node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codesEPSS 0.3%CVE-2026-22603MEDIUMOpenProject has no protection against brute-force attacks in the Change Password functionEPSS 0.3%CVE-2026-56592MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.3%