Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2025-14362HIGHGoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain CircumstancesEPSS 0.2%CVE-2026-92082MEDIUMPayara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attemptsEPSS 0.2%CVE-2024-38888MEDIUMAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker toEPSS 0.2%CVE-2026-1816MEDIUMOTP Bypass in TEİAŞ's Mobile ApplicationEPSS 0.2%CVE-2026-36607HIGHMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpEPSS 0.2%CVE-2026-86186MEDIUMAVideo API Rate Limit Bypass via Bot User-Agent HeaderEPSS 0.2%CVE-2026-58271MEDIUM@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`EPSS 0.2%CVE-2026-35902MEDIUMThe RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedlyEPSS 0.2%CVE-2024-9832CRITICALNo limit on failed login attempts with Clinician Password or Serial Number Clinician Password on Life2000 VentilatorEPSS 0.2%CVE-2025-62313MEDIUMHCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced.EPSS 0.2%CVE-2026-49324MEDIUMIndian Scout Bobber 2025 WCM brute-forceEPSS 0.2%CVE-2025-0417HIGHValmet DNA Lack of protection against brute force attacksEPSS 0.2%CVE-2023-3669LOWCODESYS: Missing Brute-Force protection in CODESYS Development SystemEPSS 0.1%CVE-2026-27824MEDIUMcalibre has IP Ban Bypass via X-Forwarded-For Header SpoofingEPSS 0.1%CVE-2026-36612MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-second lockout after 10 aEPSS 0.1%CVE-2025-54860MEDIUMCognex In-Sight Explorer and In-Sight Camera Firmware Improper Restriction of Excessive Authentication AttemptsEPSS 0.1%CVE-2025-12896MEDIUMImproper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authoriEPSS 0.1%CVE-2026-20512MEDIUMIn Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilegeEPSS 0.1%CVE-2026-20514MEDIUMIn Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure EPSS 0.1%CVE-2026-31863LOWImproper Restriction of Excessive Authentication Attempts in github.com/anyproto/anytype-heartEPSS 0.1%