Fallos del tipo CWE-307

484 resultados

Falta de limitação em tentativas de autenticação

É quando a aplicação não restringe adequadamente quantas vezes um atacante pode tentar adivinhar credenciais (senha, PIN, código MFA). Sem limite de tentativas ou delay entre elas, força bruta fica viável: o atacante testa combinações até encontrar a senha correta.

Ejemplo

Um formulário de login que aceita requisições ilimitadas sem rate limiting — alguém escreve um script que testa 10 mil senhas por segundo contra uma conta específica até acertar. Ou um endpoint de recuperação de senha que valida códigos sem contar quantas tentativas erradas já houve.

Cómo mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em janela de tempo), aumente delay exponencial entre tentativas falhadas, bloqueie a conta ou IP temporariamente após N falhas, e use CAPTCHA ou MFA para dificultar automação. Log de tentativas suspeitas é essencial para detecção.

CVE-2022-31228HIGHDell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability. A remote unauthenticated attacker can potentially exploitEPSS 0.8%CVE-2022-45893HIGHPlanet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changingEPSS 0.8%CVE-2022-43904HIGHIBM Security Guardium information disclosureEPSS 0.8%CVE-2023-28847LOWNextcloud Server missing brute force protection for passwords of password protected share linksEPSS 0.8%CVE-2023-6928CRITICALImproper Restriction of Excessive Authentication AttemptsEPSS 0.8%CVE-2022-2525CRITICALImproper Restriction of Excessive Authentication Attempts in janeczku/calibre-webEPSS 0.8%CVE-2021-3412—It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login conEPSS 0.8%CVE-2024-2051CRITICAL CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized EPSS 0.8%CVE-2023-41350HIGHChunghwa Telecom NOKIA G-040W-Q - Excessive Authentication AttemptsEPSS 0.8%CVE-2024-21652CRITICALArgo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data LossEPSS 0.8%CVE-2024-1104HIGHTemporary denial of service during a brute force attackEPSS 0.7%CVE-2023-43699HIGH Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the passworEPSS 0.7%CVE-2018-19021—A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3EPSS 0.7%CVE-2022-4797CRITICALImproper Restriction of Excessive Authentication Attempts in usememos/memosEPSS 0.7%CVE-2023-39958MEDIUMMissing brute force protection on password reset token OAuth2 API controllerEPSS 0.7%CVE-2026-50176HIGHEVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication AttemptsEPSS 0.7%CVE-2021-3663MEDIUMImproper Restriction of Excessive Authentication Attempts in firefly-iii/firefly-iiiEPSS 0.7%CVE-2026-2110MEDIUMTasin1025 SwiftBuy login.php excessive authenticationEPSS 0.7%CVE-2023-46123MEDIUMjumpserver is vulnerable to password brute-force protection bypass via arbitrary IP valuesEPSS 0.7%CVE-2021-38474MEDIUMInHand Networks IR615 RouterEPSS 0.7%