CWE一覧に戻る
CWE-307

過剰な認証試行の不適切な制限

Improper Restriction of Excessive Authentication Attempts
脆弱性 レビュー中
JA

この製品には、短時間に何度も認証に失敗することを防ぐための十分な対策が施されていない。

EN

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Scope: Access Control / Impact: Bypass Protection Mechanism
Common protection mechanisms include:
Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].

Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]
MITRE公式ページ — CWE-307