Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2025-14362HIGHGoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain CircumstancesEPSS 0.2%CVE-2026-92082MEDIUMPayara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attemptsEPSS 0.2%CVE-2024-38888MEDIUMAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker toEPSS 0.2%CVE-2026-1816MEDIUMOTP Bypass in TEİAŞ's Mobile ApplicationEPSS 0.2%CVE-2026-36607HIGHMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpEPSS 0.2%CVE-2026-86186MEDIUMAVideo API Rate Limit Bypass via Bot User-Agent HeaderEPSS 0.2%CVE-2026-58271MEDIUM@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`EPSS 0.2%CVE-2026-35902MEDIUMThe RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedlyEPSS 0.2%CVE-2024-9832CRITICALNo limit on failed login attempts with Clinician Password or Serial Number Clinician Password on Life2000 VentilatorEPSS 0.2%CVE-2025-62313MEDIUMHCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced.EPSS 0.2%CVE-2026-49324MEDIUMIndian Scout Bobber 2025 WCM brute-forceEPSS 0.2%CVE-2025-0417HIGHValmet DNA Lack of protection against brute force attacksEPSS 0.2%CVE-2023-3669LOWCODESYS: Missing Brute-Force protection in CODESYS Development SystemEPSS 0.1%CVE-2026-27824MEDIUMcalibre has IP Ban Bypass via X-Forwarded-For Header SpoofingEPSS 0.1%CVE-2026-36612MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-second lockout after 10 aEPSS 0.1%CVE-2025-54860MEDIUMCognex In-Sight Explorer and In-Sight Camera Firmware Improper Restriction of Excessive Authentication AttemptsEPSS 0.1%CVE-2025-12896MEDIUMImproper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authoriEPSS 0.1%CVE-2026-20512MEDIUMIn Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilegeEPSS 0.1%CVE-2026-20514MEDIUMIn Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure EPSS 0.1%CVE-2026-31863LOWImproper Restriction of Excessive Authentication Attempts in github.com/anyproto/anytype-heartEPSS 0.1%