Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2024-3461MEDIUMKioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as tEPSS 0.3%CVE-2026-66340MEDIUMMira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attemptsEPSS 0.3%CVE-2026-27521MEDIUMBinardat 10G08-0800GSM Network Switch Missing Login Rate LimitingEPSS 0.3%CVE-2026-40538LOWAn improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-EPSS 0.2%CVE-2024-25031MEDIUMIBM Storage Defender information disclosureEPSS 0.2%CVE-2025-67090MEDIUMThe LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 VersionEPSS 0.2%CVE-2026-15144HIGH@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotationEPSS 0.2%CVE-2025-7630MEDIUMOTP Password Brute Forcing in DorukNet's WispotterEPSS 0.2%CVE-2026-35646MEDIUMOpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token ValidationEPSS 0.2%CVE-2025-36363MEDIUMIBM DevOps Plan is vulnerable to Excessive Authentication AttemptsEPSS 0.2%CVE-2025-1629MEDIUMExcitel Broadband Private my Excitel App One-Time Password excessive authenticationEPSS 0.2%CVE-2026-92583MEDIUMAVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter IncrementEPSS 0.2%CVE-2023-25820MEDIUMNextcloud Server and Enterprise Server missing brute force protection on password confirmation modalEPSS 0.2%CVE-2026-16619HIGHminiOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor AttemptsEPSS 0.2%CVE-2025-46603HIGHDell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentication Attempts vulneEPSS 0.2%CVE-2021-36284MEDIUMDell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administratorEPSS 0.2%CVE-2021-36285MEDIUMDell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administratorEPSS 0.2%CVE-2026-75575MEDIUMRocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor MethodEPSS 0.2%CVE-2025-31991MEDIUMHCL DevOps Velocity is susceptible to brute-force attacksEPSS 0.2%CVE-2024-42176LOWHCL MyXalytics is affected by concurrent login vulnerabilityEPSS 0.2%