BaseDraft

CWE-307Improper Restriction of Excessive Authentication Attempts

Category: auth

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Common consequences· 1

  • Access Control — Bypass Protection Mechanism
    An attacker could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account using a brute force attack.

Potential mitigations· 2

  • [Architecture and Design]
  • [Architecture and Design]

Related CAPEC attack patterns· 7

CAPEC-16CAPEC-49CAPEC-560CAPEC-565CAPEC-600CAPEC-652CAPEC-653

References

  1. https://cwe.mitre.org/data/definitions/307.html

Exploits (incoming)7

TypeTargetConfidenceTier
AttackPatternPassword Sprayingcapec-565100%live
AttackPatternUse of Known Operating System Credentialscapec-653100%live
AttackPatternUse of Known Domain Credentialscapec-560100%live
AttackPatternPassword Brute Forcingcapec-49100%live
AttackPatternDictionary-based Password Attackcapec-16100%live
AttackPatternCredential Stuffingcapec-600100%live
AttackPatternUse of Known Kerberos Credentialscapec-652100%live

Compliance frameworks addressing this (incoming)5

TypeTargetConfidenceTier
ComplianceControlowasp_api_top10-api04100%live
ComplianceControliso27001-a.8.5100%live
ComplianceControlpci_dss_v4-r8100%live
ComplianceControlowasp_top10-a07100%live
ComplianceControlnis2-art21g100%live

(incoming)56

TypeTargetConfidenceTier
VulnerabilityCVE-2025-12547cve-2025-125470%live
VulnerabilityCVE-2025-12995cve-2025-129950%live
VulnerabilityCVE-2025-1710cve-2025-17100%live
VulnerabilityCVE-2025-1740cve-2025-17400%live
VulnerabilityCVE-2025-1928cve-2025-19280%live
VulnerabilityCVE-2025-23368cve-2025-233680%live
VulnerabilityCVE-2025-2411cve-2025-24110%live
VulnerabilityCVE-2025-2412cve-2025-24120%live
VulnerabilityCVE-2025-2413cve-2025-24130%live
VulnerabilityCVE-2025-2414cve-2025-24140%live
VulnerabilityCVE-2025-2415cve-2025-24150%live
VulnerabilityCVE-2025-2416cve-2025-24160%live
VulnerabilityCVE-2025-2417cve-2025-24170%live
VulnerabilityCVE-2025-25595cve-2025-255950%live
VulnerabilityCVE-2025-27449cve-2025-274490%live
VulnerabilityCVE-2025-27456cve-2025-274560%live
VulnerabilityCVE-2025-31676cve-2025-316760%live
VulnerabilityCVE-2025-3555cve-2025-35550%live
VulnerabilityCVE-2025-3556cve-2025-35560%live
VulnerabilityCVE-2025-3709cve-2025-37090%live
VulnerabilityCVE-2025-4319cve-2025-43190%live
VulnerabilityCVE-2025-4383cve-2025-43830%live
VulnerabilityCVE-2025-43863cve-2025-438630%live
VulnerabilityCVE-2025-46414cve-2025-464140%live
VulnerabilityCVE-2025-46739cve-2025-467390%live
VulnerabilityCVE-2025-48187cve-2025-481870%live
VulnerabilityCVE-2025-49195cve-2025-491950%live
VulnerabilityCVE-2025-56221cve-2025-562210%live
VulnerabilityCVE-2025-56224cve-2025-562240%live
VulnerabilityCVE-2025-58587cve-2025-585870%live

Showing top 30 of 56 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Weak Authentication
CWE
Improper Access Control
CWE
Insufficiently Protected Credentials
CWE
Missing Critical Step in Authentication
CWE
Use of Single-factor Authentication
CWE
Overly Restrictive Account Lockout Mechanism
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.