Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2022-22561HIGHDell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remoEPSS 1.4%CVE-2023-32224CRITICALD-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication AttemptsEPSS 1.4%CVE-2021-28248HIGHCA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is ablEPSS 1.4%CVE-2021-32522CRITICALQSAN Storage Manager, XEVO, SANOS - Improper Restriction of Excessive Authentication AttemptsEPSS 1.4%CVE-2021-42544HIGHLack of Rate limiting in Authentication in TopEaseEPSS 1.4%CVE-2020-10285CRITICALRVD#3322: Weak authentication implementation make the system vulnerable to a brute-force attack over adjacent networksEPSS 1.3%CVE-2020-8202Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long paEPSS 1.3%CVE-2019-18261In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implemEPSS 1.3%CVE-2021-25676A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >EPSS 1.3%CVE-2023-6756MEDIUMThecosy IceCMS Captcha login excessive authenticationEPSS 1.3%CVE-2019-0039MEDIUMJunos OS: Login credentials are vulnerable to brute force attacks through the REST APIEPSS 1.3%CVE-2021-1311MEDIUMCisco Webex Meetings and Cisco Webex Meetings Server Host Key Brute Forcing VulnerabilityEPSS 1.3%CVE-2020-14484OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute fEPSS 1.2%CVE-2024-57610HIGHA rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly EPSS 1.2%CVE-2024-3202LOWcodelyfe Stupid Simple CMS Login Page excessive authenticationEPSS 1.2%CVE-2018-14657MEDIUMA flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm EPSS 1.2%CVE-2022-3993CRITICALImproper Restriction of Excessive Authentication Attempts in kareadita/kavitaEPSS 1.2%CVE-2023-3173CRITICALImproper Restriction of Excessive Authentication Attempts in froxlor/froxlorEPSS 1.1%CVE-2022-37772HIGHMaarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the aEPSS 1.1%CVE-2022-2166CRITICALImproper Restriction of Excessive Authentication Attempts in mastodon/mastodonEPSS 1.1%