CWE-307: Improper Restriction of Excessive Authentication Attempts

What is CWE-307?

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Analyzing data...

Data statistics

OWASP TOP 10:2025 RANK7 — A07:2025 — Authentication Failures
RELATED CVES (365 DAYS)92
ABSTRACTIONBase

Vulnerabilities mapped to CWE-307

92 vulnerabilities217.2% increase year over year

Vulnerabilities in CISA KEV for CWE-307

0 vulnerabilities

Official definition

ByMitre CWE

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Characteristics

Modes of introduction

  • Architecture and Design: COMMISSION: This weakness refers to an incorrect design related to an architectural security tactic.

Common consequences

ImpactScopeExplanation
Bypass Protection MechanismAccess ControlAn attacker could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account using a brute force attack.

Risk mitigations

  1. Architecture and DesignCommon protection mechanisms include: - Disconnecting the user after a small number of failed attempts - Implementing a timeout - Locking out a targeted account - Requiring a computational task on the user's part.
  2. Libraries or Frameworks · Architecture and DesignUse a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]

Detection methods

MethodApproachEffectiveness
Dynamic Analysis with Automated Results InterpretationAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Web Application Scanner Web Services Scanner Database Scanners ``` Cost effective for partial coverage: ``` Host-based Vulnerability Scanners - Examine configuration for flaws, verifying that audit mechanisms work, ensure host configuration meets certain predefined criteriaHigh
Dynamic Analysis with Manual Results InterpretationAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Fuzz Tester Framework-based Fuzzer ``` Cost effective for partial coverage: ``` Forced Path ExecutionHigh
Manual Static Analysis - Source CodeAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)High
Automated Static Analysis - Source CodeAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Source code Weakness Analyzer Context-configured Source Code Weakness AnalyzerSOAR Partial
Automated Static AnalysisAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Configuration CheckerSOAR Partial
Architecture or Design ReviewAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Formal Methods / Correct-By-Construction ``` Cost effective for partial coverage: ``` Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)High

Representative vulnerabilities

Sources (5)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan