Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2022-3031LOWAn issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versioEPSS 0.6%CVE-2023-36917MEDIUMPassword Change rate limit bypass in SAP BusinessObjects Business Intelligence PlatformEPSS 0.6%CVE-2026-56450MEDIUMAIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Authentication CodesEPSS 0.6%CVE-2026-14254HIGHImproper Restriction of Excessive Authentication Attempts in Delphix Continuous DataEPSS 0.6%CVE-2023-39960MEDIUMNextcloud Server has improper restriction of excessive authentication attempts on WebDAV endpointEPSS 0.6%CVE-2024-49597HIGHDell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. EPSS 0.6%CVE-2025-8742MEDIUMmacrozheng mall Admin Login excessive authenticationEPSS 0.6%CVE-2024-51558CRITICALBrute Force Attack Vulnerability in Wave 2.0EPSS 0.6%CVE-2026-7671MEDIUMCodeWise Tornet Scooter Mobile App TwoFactor excessive authenticationEPSS 0.6%CVE-2026-35098MEDIUMImproper Restriction of Excessive Authentication Attempts in KTM System e-BOKEPSS 0.6%CVE-2024-45790CRITICALUser Enumeration vulnerabilityEPSS 0.6%CVE-2024-47088CRITICALUser Enumeration vulnerabilityEPSS 0.6%CVE-2026-93650MEDIUMSaleor throttling.py get_client_ip excessive authenticationEPSS 0.6%CVE-2023-3548HIGHIQ Wifi 6EPSS 0.5%CVE-2023-42480MEDIUMInformation Disclosure in NetWeaver AS Java LogonEPSS 0.5%CVE-2024-46442CRITICALAn issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.EPSS 0.5%CVE-2025-27456HIGHCVE-2025-27456EPSS 0.5%CVE-2025-1710HIGHCVE-2025-1710EPSS 0.5%CVE-2025-27449HIGHCVE-2025-27449EPSS 0.5%CVE-2025-11566MEDIUMCWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on the local network toEPSS 0.5%