目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-307 过多认证尝试的限制不恰当 类漏洞列表 410

CWE-307 过多认证尝试的限制不恰当 类弱点 410 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-307 属于身份验证缺陷,指系统未有效限制短时间内过多的认证失败尝试。攻击者常利用此漏洞进行暴力破解或字典攻击,通过高频尝试猜测凭证以获取未授权访问。开发者应实施账户锁定机制、引入验证码挑战或设置动态速率限制,从而在保障用户体验的同时,显著增加自动化攻击的难度与成本,确保系统安全性。

MITRE CWE 官方描述
CWE:CWE-307 过度身份验证尝试的限制不当 英文:产品未实施足够的措施来防止在短时间内发生多次失败的身份验证尝试。
常见影响 (1)
Access Control Bypass Protection Mechanism
An attacker could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account using a brute force attack.
缓解措施 (2)
Architecture and Design Common protection mechanisms include: Disconnecting the user after a small number of failed attempts Implementing a timeout Locking out a targeted account Requiring a computational task on the user's part.
Architecture and Design Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]
代码示例 (2)
In January 2009, an attacker was able to gain administrator access to a Twitter server because the server did not restrict the number of login attempts [REF-236]. The attacker targeted a member of Twitter's support team and was able to successfully guess the member's password using a brute force attack by guessing a large number of common words. After gaining access as the member of the support st…
The following code, extracted from a servlet's doPost() method, performs an authentication lookup every time the servlet is invoked.
String username = request.getParameter("username"); String password = request.getParameter("password"); int authResult = authenticateUser(username, password);
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2022-31234 Dell EMC PowerStore 安全漏洞 — PowerStore 8.1 High 2022-07-20
CVE-2022-2321 Nakama 安全漏洞 — heroiclabs/nakama 9.8 - 2022-07-05
CVE-2022-30235 Schneider Electric PowerLogic ION Setup 安全漏洞 — Wiser Smart 8.6 High 2022-06-02
CVE-2022-29084 多款Dell产品安全漏洞 — Unity 8.1 High 2022-06-02
CVE-2022-24044 多款Siemens产品安全漏洞 — Desigo DXR2 7.5 - 2022-05-10
CVE-2022-26519 Interlogix Hills ComNav 安全漏洞 — Hills ComNav 5.5 Medium 2022-04-20
CVE-2022-22561 Dell Technologies Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS 8.1 High 2022-04-12
CVE-2022-25820 Samsung fingerprint matching algorithm 安全漏洞 — Samsung Mobile Devices 4.2 Medium 2022-03-08
CVE-2022-26314 Siemens Mendix 安全漏洞 — Mendix Forgot Password Appstore module 9.8 - 2022-03-08
CVE-2022-22810 Schneider Electric 多款产品安全漏洞 — spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior) 9.8 - 2022-02-09
CVE-2022-22553 DELL EMC AppSync 安全漏洞 — AppSync 8.1 High 2022-01-21
CVE-2021-41807 M-Files Web 和 M-Files Server 安全漏洞 — M-Files Server 7.5 High 2022-01-18
CVE-2021-42544 Business-Dna Solution GmbH TopEase 安全漏洞 — TopEase 7.5 High 2021-11-30
CVE-2021-41171 eLabFTW 安全漏洞 — elabftw 5.9 Medium 2021-10-22
CVE-2021-38474 IR615 Router 安全漏洞 — IR615 Router 6.3 Medium 2021-10-19
CVE-2021-36285 Dell BIOS 安全漏洞 — CPG BIOS 5.7 Medium 2021-09-28
CVE-2021-36284 Dell BIOS 安全漏洞 — CPG BIOS 5.7 Medium 2021-09-28
CVE-2021-3663 firefly-iii 安全漏洞 — firefly-iii/firefly-iii 7.5 - 2021-07-25
CVE-2021-32522 QSAN 多款产品安全漏洞 — Storage Manager 9.8 Critical 2021-07-07
CVE-2021-22915 Nextcloud server 处理逻辑错误漏洞 — Nextcloud Server 9.8 - 2021-06-11
CVE-2021-33190 Apache Apisix 安全漏洞 — Apache APISIX Dashboard 5.3 - 2021-06-08
CVE-2021-3412 3Scale 安全漏洞 — 3Scale 8.6 - 2021-06-01
CVE-2021-22737 Schneider Electric homeLYnk和spaceLYnk 安全漏洞 — homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior 9.8 - 2021-05-26
CVE-2019-18235 None Advantech Spectre RT ERT351 firmware 安全漏洞 — Advantech Spectre RT ERT351 Versions 5.1.3 and prior 9.8 - 2021-03-17
CVE-2021-25676 Siemens RUGGEDCOM 安全漏洞 — RUGGEDCOM RM1224 7.5 - 2021-03-15
CVE-2021-1311 Cisco Webex Meetings 安全漏洞 — Cisco WebEx Meetings Server 5.4 Medium 2021-01-13
CVE-2020-25196 Moxa NPort IAW5000A-I/O 安全漏洞 — NPort IAW5000A-I/O 9.8 Critical 2020-12-23
CVE-2020-28212 Schneider Electric EcoStruxure Control Expert 授权问题漏洞 — PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) 9.8 - 2020-11-19
CVE-2020-15786 Siemens SIMATIC HMI/WinCC 安全漏洞 — SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) 9.1 - 2020-09-09
CVE-2020-7525 Schneider 安全漏洞 — All hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) 7.5 - 2020-08-31

CWE-307(过多认证尝试的限制不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 410 条 CVE 漏洞。