Fallos del tipo CWE-307

431 resultados

Falta de limitação em tentativas de autenticação

É quando a aplicação não restringe adequadamente quantas vezes um atacante pode tentar adivinhar credenciais (senha, PIN, código MFA). Sem limite de tentativas ou delay entre elas, força bruta fica viável: o atacante testa combinações até encontrar a senha correta.

Ejemplo

Um formulário de login que aceita requisições ilimitadas sem rate limiting — alguém escreve um script que testa 10 mil senhas por segundo contra uma conta específica até acertar. Ou um endpoint de recuperação de senha que valida códigos sem contar quantas tentativas erradas já houve.

Cómo mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em janela de tempo), aumente delay exponencial entre tentativas falhadas, bloqueie a conta ou IP temporariamente após N falhas, e use CAPTCHA ou MFA para dificultar automação. Log de tentativas suspeitas é essencial para detecção.

CVE-2022-22553HIGHDell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploiteEPSS 1.1%CVE-2024-41276CRITICALA vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application reEPSS 1.1%CVE-2022-3993CRITICALImproper Restriction of Excessive Authentication Attempts in kareadita/kavitaEPSS 1.1%CVE-2023-49792MEDIUMBruteforce protection can be bypassed with misconfigured proxyEPSS 1.0%CVE-2024-22317CRITICALIBM App Connect Enterprise denial of serviceEPSS 1.0%CVE-2022-2166CRITICALImproper Restriction of Excessive Authentication Attempts in mastodon/mastodonEPSS 1.0%CVE-2022-31234HIGHDell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remoEPSS 1.0%CVE-2026-1685MEDIUMD-Link DIR-823X Login sub_40AC74 excessive authenticationEPSS 1.0%CVE-2024-24767CRITICALCasaOS Improper Restriction of Excessive Authentication Attempts vulnerabilityEPSS 1.0%CVE-2023-6912HIGHBrute force vulnerability in M-Files user authenticationEPSS 1.0%CVE-2021-22737Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthoEPSS 0.9%CVE-2023-4625MEDIUMDenial-of-Service(DoS) Vulnerability in Web server function on MELSEC Series CPU moduleEPSS 0.9%CVE-2022-30235HIGHA CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacEPSS 0.9%CVE-2024-45589MEDIUMRapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote atEPSS 0.9%CVE-2024-23106HIGHAn improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allowEPSS 0.9%CVE-2023-24080CRITICALA lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounEPSS 0.9%CVE-2024-38176HIGHGroupMe Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-35172HIGHNextcloud Server password reset endpoint is not brute force protectedEPSS 0.9%CVE-2025-3556MEDIUMScriptAndTools eCommerce-website-in-PHP login.php excessive authenticationEPSS 0.9%CVE-2025-3555MEDIUMScriptAndTools eCommerce-website-in-PHP login.php excessive authenticationEPSS 0.9%