Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2026-11915MEDIUMBrute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047EPSS 0.3%CVE-2024-24721MEDIUMAn issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack throughEPSS 0.3%CVE-2024-47592MEDIUMInformation Disclosure Vulnerability in SAP NetWeaver Application Server Java (Logon Application)EPSS 0.3%CVE-2022-40903MEDIUMAiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access attempts, which allowsEPSS 0.3%CVE-2025-7882LOWMercusys MW301R Login excessive authenticationEPSS 0.3%CVE-2026-73045HIGHSiYuan before 3.7.4 Brute-Force via authFilePublishAccessEPSS 0.3%CVE-2026-40586HIGHblueprintUE: Login Endpoint Has No Rate Limiting, Lockout, or Brute-Force ProtectionEPSS 0.3%CVE-2025-2514MEDIUMImproper Restriction of Excessive Authentication Attempts vulnerability in Hitachi Virtual Storage PlatformEPSS 0.3%CVE-2026-73529MEDIUMPlainpad Missing Rate Limiting via POST /v1/sessionsEPSS 0.3%CVE-2024-53647MEDIUMTrend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email veEPSS 0.3%CVE-2025-52916LOWYealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).EPSS 0.3%CVE-2026-35597MEDIUMVikunja Affected by TOTP Brute-Force Due to Non-Functional Account LockoutEPSS 0.3%CVE-2026-33667HIGHOpenProject: 2FA OTP Verification Missing Rate LimitingEPSS 0.3%CVE-2026-55795MEDIUMCraft Commerce: Coupon Code Brute-Force via Rate Limit BypassEPSS 0.3%CVE-2025-57815LOWFides Lacks Brute-Force Protections on Authentication EndpointsEPSS 0.3%CVE-2026-45364HIGHBetter Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotationEPSS 0.3%CVE-2024-11126LOWDigistar AG-30 Plus Login Page excessive authenticationEPSS 0.3%CVE-2026-78490HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper RestrictEPSS 0.3%CVE-2026-43914HIGHVaultwarden: Brute-force protection bypass vulnerabilityEPSS 0.3%CVE-2026-26227MEDIUMVLC for Android < 3.7.0 Remote Access OTP Authentication BypassEPSS 0.3%