Weaknesses of type CWE-640

195 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2023-7028CRITICALWeak Password Recovery Mechanism for Forgotten Password in GitLabEPSS 94.6%KEVCVE-2025-6216CRITICALAllegra calculateTokenExpDate Password Recovery Authentication Bypass VulnerabilityEPSS 34.5%CVE-2025-47646CRITICALWordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication VulnerabilityEPSS 24.3%CVE-2021-22763CRITICALA CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EPSS 1.9%CVE-2018-16529A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intendedEPSS 1.6%CVE-2022-29174HIGHPredictable password reset token may lead to account takeover in countly-serverEPSS 1.4%CVE-2021-22731Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior wEPSS 1.4%CVE-2024-8878CRITICALUnauthenticated Password ResetEPSS 1.3%CVE-2022-0777HIGHWeak Password Recovery Mechanism for Forgotten Password in microweber/microweberEPSS 1.2%CVE-2022-44004CRITICALAn issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can coEPSS 1.2%CVE-2023-30466CRITICALAuthentication Bypass Vulnerability in Milesight Network Video Recorder (NVR)EPSS 1.1%CVE-2019-6560In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a EPSS 1.1%CVE-2026-7554MEDIUMD-Link M60 httpd password recoveryEPSS 1.1%CVE-2021-25957HIGHAccount Takeover in "Dolibarr" via Password Reset FunctionalityEPSS 1.1%CVE-2023-3007MEDIUMningzichun Student Management System Password Reset resetPassword.php password recoveryEPSS 1.0%CVE-2023-36487The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.EPSS 1.0%CVE-2025-41251HIGHWeak password recovery vulnerabilityEPSS 1.0%CVE-2022-22691MEDIUMUmbraco Password Reset URL PoisonEPSS 1.0%CVE-2021-36804MEDIUMAkaunting Password Reset RelayEPSS 1.0%CVE-2021-25961HIGHSuiteCRM - Account Takeover in Password Reset FunctionalityEPSS 1.0%