Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2022-31228HIGHDell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability. A remote unauthenticated attacker can potentially exploitEPSS 0.8%CVE-2022-45893HIGHPlanet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changingEPSS 0.8%CVE-2023-28847LOWNextcloud Server missing brute force protection for passwords of password protected share linksEPSS 0.8%CVE-2022-43904HIGHIBM Security Guardium information disclosureEPSS 0.8%CVE-2023-6928CRITICALImproper Restriction of Excessive Authentication AttemptsEPSS 0.8%CVE-2022-2525CRITICALImproper Restriction of Excessive Authentication Attempts in janeczku/calibre-webEPSS 0.8%CVE-2021-3412It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login conEPSS 0.8%CVE-2024-2051CRITICAL CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized EPSS 0.8%CVE-2023-41350HIGHChunghwa Telecom NOKIA G-040W-Q - Excessive Authentication AttemptsEPSS 0.8%CVE-2024-21652CRITICALArgo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data LossEPSS 0.8%CVE-2024-1104HIGHTemporary denial of service during a brute force attackEPSS 0.7%CVE-2023-43699HIGH Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the passworEPSS 0.7%CVE-2018-19021A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3EPSS 0.7%CVE-2022-4797CRITICALImproper Restriction of Excessive Authentication Attempts in usememos/memosEPSS 0.7%CVE-2023-39958MEDIUMMissing brute force protection on password reset token OAuth2 API controllerEPSS 0.7%CVE-2026-50176HIGHEVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication AttemptsEPSS 0.7%CVE-2021-3663MEDIUMImproper Restriction of Excessive Authentication Attempts in firefly-iii/firefly-iiiEPSS 0.7%CVE-2026-2110MEDIUMTasin1025 SwiftBuy login.php excessive authenticationEPSS 0.7%CVE-2023-46123MEDIUMjumpserver is vulnerable to password brute-force protection bypass via arbitrary IP valuesEPSS 0.7%CVE-2021-38474MEDIUMInHand Networks IR615 RouterEPSS 0.7%