Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2026-31851HIGHNexxt Nebula 300+ - Lack of Rate Limiting Enables Brute-Force AttacksEPSS 0.3%CVE-2026-76213CRITICALphpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped ThrottleEPSS 0.3%CVE-2026-69183HIGHMonkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass)EPSS 0.3%CVE-2025-6015MEDIUMVault Login MFA Bypass of Rate Limiting and TOTP Code ReuseEPSS 0.3%CVE-2026-27753MEDIUMSODOLA SL902-SWTGW124AS <= 200.1.20 Improper Login Rate LimitingEPSS 0.3%CVE-2026-41893HIGHSignal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)EPSS 0.3%CVE-2025-35041HIGHAirship AI Acropolis MFA insufficient rate limitingEPSS 0.3%CVE-2026-35675HIGHphpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/updateEPSS 0.3%CVE-2026-78617MEDIUMWatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate LimitingEPSS 0.3%CVE-2026-71213CRITICALtypemill - No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-ForceEPSS 0.3%CVE-2024-38488MEDIUMDell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability wheEPSS 0.3%CVE-2026-33763MEDIUMAVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean OracleEPSS 0.3%CVE-2024-51720MEDIUMVulnerabilities in SecuSUITE Server Components Impact SecuSUITEEPSS 0.3%CVE-2026-22616MEDIUMEaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insuffiEPSS 0.3%CVE-2026-44195MEDIUMOPNsense: Authentication lockout bypassEPSS 0.3%CVE-2026-47380MEDIUMNocoDB: User Enumeration via Sign-In TimingEPSS 0.3%CVE-2023-48318MEDIUMWordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerabilityEPSS 0.3%CVE-2026-32025HIGHOpenClaw < 2026.2.25 - Password Brute-Force via Browser-Origin WebSocket Authentication BypassEPSS 0.3%CVE-2026-13348MEDIUMCWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized acEPSS 0.3%CVE-2025-2911MEDIUMImproper Restriction of Excessive Authentication Attempts vulnerability in MeetMe productsEPSS 0.3%