Fallos del tipo CWE-307

431 resultados

Falta de limitação em tentativas de autenticação

É quando a aplicação não restringe adequadamente quantas vezes um atacante pode tentar adivinhar credenciais (senha, PIN, código MFA). Sem limite de tentativas ou delay entre elas, força bruta fica viável: o atacante testa combinações até encontrar a senha correta.

Ejemplo

Um formulário de login que aceita requisições ilimitadas sem rate limiting — alguém escreve um script que testa 10 mil senhas por segundo contra uma conta específica até acertar. Ou um endpoint de recuperação de senha que valida códigos sem contar quantas tentativas erradas já houve.

Cómo mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em janela de tempo), aumente delay exponencial entre tentativas falhadas, bloqueie a conta ou IP temporariamente após N falhas, e use CAPTCHA ou MFA para dificultar automação. Log de tentativas suspeitas é essencial para detecção.

CVE-2020-1616MEDIUMJATP Series: JATP Is susceptible to slow brute force attacks on the SSH service.EPSS 1.4%CVE-2021-28248HIGHCA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is ablEPSS 1.4%CVE-2021-32522CRITICALQSAN Storage Manager, XEVO, SANOS - Improper Restriction of Excessive Authentication AttemptsEPSS 1.4%CVE-2021-42544HIGHLack of Rate limiting in Authentication in TopEaseEPSS 1.4%CVE-2022-22561HIGHDell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remoEPSS 1.4%CVE-2020-10285CRITICALRVD#3322: Weak authentication implementation make the system vulnerable to a brute-force attack over adjacent networksEPSS 1.3%CVE-2020-8202Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long paEPSS 1.3%CVE-2019-18261In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implemEPSS 1.3%CVE-2021-25676A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >EPSS 1.3%CVE-2023-6756MEDIUMThecosy IceCMS Captcha login excessive authenticationEPSS 1.3%CVE-2019-0039MEDIUMJunos OS: Login credentials are vulnerable to brute force attacks through the REST APIEPSS 1.3%CVE-2021-1311MEDIUMCisco Webex Meetings and Cisco Webex Meetings Server Host Key Brute Forcing VulnerabilityEPSS 1.3%CVE-2020-14484OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute fEPSS 1.2%CVE-2024-3202LOWcodelyfe Stupid Simple CMS Login Page excessive authenticationEPSS 1.2%CVE-2024-57610HIGHA rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly EPSS 1.2%CVE-2018-14657MEDIUMA flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm EPSS 1.2%CVE-2023-3173CRITICALImproper Restriction of Excessive Authentication Attempts in froxlor/froxlorEPSS 1.1%CVE-2021-41807HIGHLack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.EPSS 1.1%CVE-2022-37772HIGHMaarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the aEPSS 1.1%CVE-2022-22810A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admEPSS 1.1%