Fallos del tipo CWE-307

484 resultados

Falta de limitação em tentativas de autenticação

É quando a aplicação não restringe adequadamente quantas vezes um atacante pode tentar adivinhar credenciais (senha, PIN, código MFA). Sem limite de tentativas ou delay entre elas, força bruta fica viável: o atacante testa combinações até encontrar a senha correta.

Ejemplo

Um formulário de login que aceita requisições ilimitadas sem rate limiting — alguém escreve um script que testa 10 mil senhas por segundo contra uma conta específica até acertar. Ou um endpoint de recuperação de senha que valida códigos sem contar quantas tentativas erradas já houve.

Cómo mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em janela de tempo), aumente delay exponencial entre tentativas falhadas, bloqueie a conta ou IP temporariamente após N falhas, e use CAPTCHA ou MFA para dificultar automação. Log de tentativas suspeitas é essencial para detecção.

CVE-2021-41807HIGHLack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.EPSS 1.1%CVE-2022-22810—A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admEPSS 1.1%CVE-2022-22553HIGHDell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploiteEPSS 1.1%CVE-2024-41276CRITICALA vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application reEPSS 1.1%CVE-2023-35039CRITICALWordPress Password Reset with Code for WordPress REST API Plugin <= 0.0.15 is vulnerable to Broken AuthenticationEPSS 1.1%CVE-2023-49792MEDIUMBruteforce protection can be bypassed with misconfigured proxyEPSS 1.0%CVE-2022-31234HIGHDell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remoEPSS 1.0%CVE-2026-1685MEDIUMD-Link DIR-823X Login sub_40AC74 excessive authenticationEPSS 1.0%CVE-2024-22317CRITICALIBM App Connect Enterprise denial of serviceEPSS 1.0%CVE-2022-3945CRITICALImproper Restriction of Excessive Authentication Attempts in kareadita/kavitaEPSS 1.0%CVE-2025-3556MEDIUMScriptAndTools eCommerce-website-in-PHP login.php excessive authenticationEPSS 1.0%CVE-2025-3555MEDIUMScriptAndTools eCommerce-website-in-PHP login.php excessive authenticationEPSS 1.0%CVE-2024-24767CRITICALCasaOS Improper Restriction of Excessive Authentication Attempts vulnerabilityEPSS 1.0%CVE-2022-30235HIGHA CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacEPSS 1.0%CVE-2023-6912HIGHBrute force vulnerability in M-Files user authenticationEPSS 1.0%CVE-2024-23106HIGHAn improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allowEPSS 1.0%CVE-2021-22737—Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthoEPSS 0.9%CVE-2023-4625MEDIUMDenial-of-Service(DoS) Vulnerability in Web server function on MELSEC Series CPU moduleEPSS 0.9%CVE-2022-3741CRITICALImproper Restriction of Excessive Authentication Attempts in chatwoot/chatwootEPSS 0.9%CVE-2024-45589MEDIUMRapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote atEPSS 0.9%