Fallos del tipo CWE-307

484 resultados

Falta de limitação em tentativas de autenticação

É quando a aplicação não restringe adequadamente quantas vezes um atacante pode tentar adivinhar credenciais (senha, PIN, código MFA). Sem limite de tentativas ou delay entre elas, força bruta fica viável: o atacante testa combinações até encontrar a senha correta.

Ejemplo

Um formulário de login que aceita requisições ilimitadas sem rate limiting — alguém escreve um script que testa 10 mil senhas por segundo contra uma conta específica até acertar. Ou um endpoint de recuperação de senha que valida códigos sem contar quantas tentativas erradas já houve.

Cómo mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em janela de tempo), aumente delay exponencial entre tentativas falhadas, bloqueie a conta ou IP temporariamente após N falhas, e use CAPTCHA ou MFA para dificultar automação. Log de tentativas suspeitas é essencial para detecção.

CVE-2024-3461MEDIUMKioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as tEPSS 0.3%CVE-2025-67090MEDIUMThe LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 VersionEPSS 0.2%CVE-2024-25031MEDIUMIBM Storage Defender information disclosureEPSS 0.2%CVE-2026-49324MEDIUMIndian Scout Bobber 2025 WCM brute-forceEPSS 0.2%CVE-2025-7630MEDIUMOTP Password Brute Forcing in DorukNet's WispotterEPSS 0.2%CVE-2026-27801MEDIUMVaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit EnforcementEPSS 0.2%CVE-2025-55003MEDIUMOpenBao Login MFA Bypasses Rate Limiting and TOTP Token ReuseEPSS 0.2%CVE-2025-36363MEDIUMIBM DevOps Plan is vulnerable to Excessive Authentication AttemptsEPSS 0.2%CVE-2025-1629MEDIUMExcitel Broadband Private my Excitel App One-Time Password excessive authenticationEPSS 0.2%CVE-2023-25820MEDIUMNextcloud Server and Enterprise Server missing brute force protection on password confirmation modalEPSS 0.2%CVE-2025-46603HIGHDell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentication Attempts vulneEPSS 0.2%CVE-2021-36285MEDIUMDell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administratorEPSS 0.2%CVE-2021-36284MEDIUMDell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administratorEPSS 0.2%CVE-2025-31991MEDIUMHCL DevOps Velocity is susceptible to brute-force attacksEPSS 0.2%CVE-2024-42176LOWHCL MyXalytics is affected by concurrent login vulnerabilityEPSS 0.2%CVE-2022-33735MEDIUMThere is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking to obtain passwordsEPSS 0.2%CVE-2025-10928MEDIUMAccess code - Moderately critical - Access bypass - SA-CONTRIB-2025-108EPSS 0.2%CVE-2025-6030CRITICALAutoeastern Smart Keyless Entry System Replay AttackEPSS 0.2%CVE-2025-8118MEDIUMBruteforce Protection Bypass in PAD CMSEPSS 0.2%CVE-2026-18260MEDIUMDisable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110EPSS 0.2%