Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2026-65948HIGHApache Ranger: UnixAuth lacks brute-force protectionEPSS 0.3%CVE-2025-2413HIGHOTP Bypass in Akinsoft's ProKuaforEPSS 0.3%CVE-2026-6853CRITICALOTP Bypass in Başbelen Group's Pause+ Mobile AppEPSS 0.3%CVE-2021-27782MEDIUMHCL BigFix Mobile / Modern Client Management Server passwords are susceptible to a brute-force attackEPSS 0.3%CVE-2025-64102HIGHZitadel allows brute-forcing authentication factorsEPSS 0.3%CVE-2026-32825HIGHdataCycle No Brute-Force Protection On Web And API Login EndpointsEPSS 0.3%CVE-2026-53904MEDIUMAccount Denial of Service in MCOEPSS 0.3%CVE-2024-45327HIGHAn improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 EPSS 0.3%CVE-2025-1496MEDIUMImproper Authentication in BG-TEK's Coslat HotspotEPSS 0.3%CVE-2026-32729HIGHRuntipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api/auth/verify-totp`EPSS 0.3%CVE-2024-49342HIGHIBM Informix Dynamic Server information disclosureEPSS 0.3%CVE-2026-45010CRITICALphpMyFAQ - Unauthenticated Two-Factor Authentication Brute-Force via /admin/check EndpointEPSS 0.3%CVE-2025-8679HIGHExtremeGuest Essentials Captive Portal Unauthenticated Brute ForceEPSS 0.3%CVE-2025-66482MEDIUMMisskey has a login rate limit bypass via spoofed X-Forwarded-For headerEPSS 0.3%CVE-2025-10658MEDIUMSupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 - Authentication Bypass to Support Session TakeoverEPSS 0.3%CVE-2025-26862NONEPingFederate unexpected browser flow initiation in redirectless modeEPSS 0.3%CVE-2025-22645MEDIUMWordPress Real Estate Manager plugin <= 7.3 - Captcha Bypass Vulnerability vulnerabilityEPSS 0.3%CVE-2026-40485MEDIUMChurchCRM: Username Enumeration via Differential Response in Public Login APIEPSS 0.3%CVE-2024-7292HIGHAccount Controller allows high count of login attemptsEPSS 0.3%CVE-2025-12995HIGHMedtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used tEPSS 0.3%