Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2021-41807HIGHLack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.EPSS 1.1%CVE-2022-22810A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admEPSS 1.1%CVE-2022-22553HIGHDell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploiteEPSS 1.1%CVE-2024-41276CRITICALA vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application reEPSS 1.1%CVE-2023-35039CRITICALWordPress Password Reset with Code for WordPress REST API Plugin <= 0.0.15 is vulnerable to Broken AuthenticationEPSS 1.1%CVE-2023-49792MEDIUMBruteforce protection can be bypassed with misconfigured proxyEPSS 1.0%CVE-2026-1685MEDIUMD-Link DIR-823X Login sub_40AC74 excessive authenticationEPSS 1.0%CVE-2022-31234HIGHDell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remoEPSS 1.0%CVE-2024-22317CRITICALIBM App Connect Enterprise denial of serviceEPSS 1.0%CVE-2022-3945CRITICALImproper Restriction of Excessive Authentication Attempts in kareadita/kavitaEPSS 1.0%CVE-2025-3555MEDIUMScriptAndTools eCommerce-website-in-PHP login.php excessive authenticationEPSS 1.0%CVE-2025-3556MEDIUMScriptAndTools eCommerce-website-in-PHP login.php excessive authenticationEPSS 1.0%CVE-2024-24767CRITICALCasaOS Improper Restriction of Excessive Authentication Attempts vulnerabilityEPSS 1.0%CVE-2022-30235HIGHA CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacEPSS 1.0%CVE-2023-6912HIGHBrute force vulnerability in M-Files user authenticationEPSS 1.0%CVE-2024-23106HIGHAn improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allowEPSS 1.0%CVE-2023-4625MEDIUMDenial-of-Service(DoS) Vulnerability in Web server function on MELSEC Series CPU moduleEPSS 0.9%CVE-2021-22737Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthoEPSS 0.9%CVE-2022-3741CRITICALImproper Restriction of Excessive Authentication Attempts in chatwoot/chatwootEPSS 0.9%CVE-2024-45589MEDIUMRapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote atEPSS 0.9%