Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2022-22561HIGHDell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remoEPSS 1.4%CVE-2023-32224CRITICALD-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication AttemptsEPSS 1.4%CVE-2021-28248HIGHCA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is ablEPSS 1.4%CVE-2021-32522CRITICALQSAN Storage Manager, XEVO, SANOS - Improper Restriction of Excessive Authentication AttemptsEPSS 1.4%CVE-2021-42544HIGHLack of Rate limiting in Authentication in TopEaseEPSS 1.4%CVE-2020-10285CRITICALRVD#3322: Weak authentication implementation make the system vulnerable to a brute-force attack over adjacent networksEPSS 1.3%CVE-2020-8202Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long paEPSS 1.3%CVE-2019-18261In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implemEPSS 1.3%CVE-2021-25676A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >EPSS 1.3%CVE-2023-6756MEDIUMThecosy IceCMS Captcha login excessive authenticationEPSS 1.3%CVE-2019-0039MEDIUMJunos OS: Login credentials are vulnerable to brute force attacks through the REST APIEPSS 1.3%CVE-2021-1311MEDIUMCisco Webex Meetings and Cisco Webex Meetings Server Host Key Brute Forcing VulnerabilityEPSS 1.3%CVE-2020-14484OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute fEPSS 1.2%CVE-2024-57610HIGHA rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly EPSS 1.2%CVE-2024-3202LOWcodelyfe Stupid Simple CMS Login Page excessive authenticationEPSS 1.2%CVE-2018-14657MEDIUMA flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm EPSS 1.2%CVE-2022-3993CRITICALImproper Restriction of Excessive Authentication Attempts in kareadita/kavitaEPSS 1.2%CVE-2023-3173CRITICALImproper Restriction of Excessive Authentication Attempts in froxlor/froxlorEPSS 1.1%CVE-2022-37772HIGHMaarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the aEPSS 1.1%CVE-2022-2166CRITICALImproper Restriction of Excessive Authentication Attempts in mastodon/mastodonEPSS 1.1%