Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2024-3461MEDIUMKioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as tEPSS 0.3%CVE-2026-66340MEDIUMMira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attemptsEPSS 0.3%CVE-2026-27521MEDIUMBinardat 10G08-0800GSM Network Switch Missing Login Rate LimitingEPSS 0.3%CVE-2026-40538LOWAn improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-EPSS 0.2%CVE-2024-25031MEDIUMIBM Storage Defender information disclosureEPSS 0.2%CVE-2025-67090MEDIUMThe LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 VersionEPSS 0.2%CVE-2026-15144HIGH@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotationEPSS 0.2%CVE-2025-7630MEDIUMOTP Password Brute Forcing in DorukNet's WispotterEPSS 0.2%CVE-2026-35646MEDIUMOpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token ValidationEPSS 0.2%CVE-2025-36363MEDIUMIBM DevOps Plan is vulnerable to Excessive Authentication AttemptsEPSS 0.2%CVE-2025-1629MEDIUMExcitel Broadband Private my Excitel App One-Time Password excessive authenticationEPSS 0.2%CVE-2026-92583MEDIUMAVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter IncrementEPSS 0.2%CVE-2023-25820MEDIUMNextcloud Server and Enterprise Server missing brute force protection on password confirmation modalEPSS 0.2%CVE-2026-16619HIGHminiOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor AttemptsEPSS 0.2%CVE-2025-46603HIGHDell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentication Attempts vulneEPSS 0.2%CVE-2021-36284MEDIUMDell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administratorEPSS 0.2%CVE-2021-36285MEDIUMDell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administratorEPSS 0.2%CVE-2026-75575MEDIUMRocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor MethodEPSS 0.2%CVE-2025-31991MEDIUMHCL DevOps Velocity is susceptible to brute-force attacksEPSS 0.2%CVE-2024-42176LOWHCL MyXalytics is affected by concurrent login vulnerabilityEPSS 0.2%