Falhas do tipo CWE-307

478 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2021-41807HIGHLack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.EPSS 1.1%CVE-2022-22810A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admEPSS 1.1%CVE-2022-22553HIGHDell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploiteEPSS 1.1%CVE-2024-41276CRITICALA vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application reEPSS 1.1%CVE-2023-35039CRITICALWordPress Password Reset with Code for WordPress REST API Plugin <= 0.0.15 is vulnerable to Broken AuthenticationEPSS 1.1%CVE-2023-49792MEDIUMBruteforce protection can be bypassed with misconfigured proxyEPSS 1.0%CVE-2026-1685MEDIUMD-Link DIR-823X Login sub_40AC74 excessive authenticationEPSS 1.0%CVE-2022-31234HIGHDell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remoEPSS 1.0%CVE-2024-22317CRITICALIBM App Connect Enterprise denial of serviceEPSS 1.0%CVE-2022-3945CRITICALImproper Restriction of Excessive Authentication Attempts in kareadita/kavitaEPSS 1.0%CVE-2025-3556MEDIUMScriptAndTools eCommerce-website-in-PHP login.php excessive authenticationEPSS 1.0%CVE-2025-3555MEDIUMScriptAndTools eCommerce-website-in-PHP login.php excessive authenticationEPSS 1.0%CVE-2024-24767CRITICALCasaOS Improper Restriction of Excessive Authentication Attempts vulnerabilityEPSS 1.0%CVE-2022-30235HIGHA CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacEPSS 1.0%CVE-2023-6912HIGHBrute force vulnerability in M-Files user authenticationEPSS 1.0%CVE-2024-23106HIGHAn improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allowEPSS 1.0%CVE-2021-22737Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthoEPSS 0.9%CVE-2023-4625MEDIUMDenial-of-Service(DoS) Vulnerability in Web server function on MELSEC Series CPU moduleEPSS 0.9%CVE-2022-3741CRITICALImproper Restriction of Excessive Authentication Attempts in chatwoot/chatwootEPSS 0.9%CVE-2024-45589MEDIUMRapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote atEPSS 0.9%