Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2022-31228HIGHDell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability. A remote unauthenticated attacker can potentially exploitEPSS 0.8%CVE-2022-45893HIGHPlanet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changingEPSS 0.8%CVE-2023-28847LOWNextcloud Server missing brute force protection for passwords of password protected share linksEPSS 0.8%CVE-2022-43904HIGHIBM Security Guardium information disclosureEPSS 0.8%CVE-2023-6928CRITICALImproper Restriction of Excessive Authentication AttemptsEPSS 0.8%CVE-2022-2525CRITICALImproper Restriction of Excessive Authentication Attempts in janeczku/calibre-webEPSS 0.8%CVE-2021-3412It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login conEPSS 0.8%CVE-2024-2051CRITICAL CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized EPSS 0.8%CVE-2023-41350HIGHChunghwa Telecom NOKIA G-040W-Q - Excessive Authentication AttemptsEPSS 0.8%CVE-2024-21652CRITICALArgo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data LossEPSS 0.8%CVE-2024-1104HIGHTemporary denial of service during a brute force attackEPSS 0.7%CVE-2023-43699HIGH Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the passworEPSS 0.7%CVE-2018-19021A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3EPSS 0.7%CVE-2022-4797CRITICALImproper Restriction of Excessive Authentication Attempts in usememos/memosEPSS 0.7%CVE-2023-39958MEDIUMMissing brute force protection on password reset token OAuth2 API controllerEPSS 0.7%CVE-2026-50176HIGHEVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication AttemptsEPSS 0.7%CVE-2021-3663MEDIUMImproper Restriction of Excessive Authentication Attempts in firefly-iii/firefly-iiiEPSS 0.7%CVE-2026-2110MEDIUMTasin1025 SwiftBuy login.php excessive authenticationEPSS 0.7%CVE-2023-46123MEDIUMjumpserver is vulnerable to password brute-force protection bypass via arbitrary IP valuesEPSS 0.7%CVE-2021-38474MEDIUMInHand Networks IR615 RouterEPSS 0.7%