NIST 800-53 r5 · Controls catalogue · Family AC
AC-7Unsuccessful Logon Attempts
Enforce a limit of {{ insert: param, ac-07_odp.01 }} consecutive invalid logon attempts by a user during a {{ insert: param, ac-07_odp.02 }} ; and Automatically {{ insert: param, ac-07_odp.03 }} when the maximum number of unsuccessful attempts is exceeded.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (16)
- T1021 Remote Services Lateral Movement
- T1021.001 Remote Desktop Protocol Lateral Movement
- T1021.004 SSH Lateral Movement
- T1078.002 Domain Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.004 Cloud Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1110 Brute Force Credential Access
- T1110.001 Password Guessing Credential Access
- T1110.002 Password Cracking Credential Access
- T1110.003 Password Spraying Credential Access
- T1110.004 Credential Stuffing Credential Access
- T1133 External Remote Services Persistence, Initial Access
- T1530 Data from Cloud Storage Collection
- T1556 Modify Authentication Process Defense Impairment, Persistence, Credential Access
- T1556.001 Domain Controller Authentication Defense Impairment, Persistence, Credential Access
- T1556.003 Pluggable Authentication Modules Defense Impairment, Persistence, Credential Access
- T1556.004 Network Device Authentication Defense Impairment, Persistence, Credential Access
Weaknesses this control addresses (1)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-307 | Improper Restriction of Excessive Authentication Attempts | 700+ | This control directly enforces limits on consecutive invalid logon attempts and automatic response (e.g., lockout) to prevent brute-force exploitation of authentication mechanisms. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-39225 UPD | 8.4 | 9.8 | 0.1453 | good |
CVE-2024-5716 UPD | 7.6 | 9.8 | 0.0160 | good |
CVE-2024-41276 UPD | 7.5 | 9.8 | 0.0107 | good |
CVE-2023-33759 UPD | 7.4 | 9.8 | 0.0080 | good |
CVE-2024-2051 UPD | 7.4 | 9.8 | 0.0076 | good |
CVE-2024-21652 UPD | 7.4 | 9.8 | 0.0075 | good |
CVE-2024-42466 UPD | 7.4 | 9.8 | 0.0065 | good |
CVE-2024-43042 UPD | 7.4 | 9.8 | 0.0063 | good |
CVE-2024-51558 | 7.4 | 9.8 | 0.0057 | good |
CVE-2026-8760 UPD | 7.4 | 9.8 | 0.0062 | good |
CVE-2024-42465 UPD | 7.3 | 9.8 | 0.0047 | good |
CVE-2024-45790 UPD | 7.3 | 9.8 | 0.0056 | good |
CVE-2024-47088 UPD | 7.3 | 9.8 | 0.0056 | good |
CVE-2024-47656 UPD | 7.3 | 9.8 | 0.0051 | good |
CVE-2024-46442 UPD | 7.3 | 9.8 | 0.0053 | good |
CVE-2025-25595 UPD | 7.3 | 9.8 | 0.0048 | good |
CVE-2025-3709 UPD | 7.3 | 9.8 | 0.0054 | good |
CVE-2025-43863 UPD | 7.3 | 9.8 | 0.0040 | good |
CVE-2024-9342 UPD | 7.3 | 9.8 | 0.0041 | good |
CVE-2025-7393 UPD | 7.3 | 9.8 | 0.0046 | good |
CVE-2025-1740 UPD | 7.3 | 9.8 | 0.0045 | good |
CVE-2025-56221 UPD | 7.3 | 9.8 | 0.0056 | good |
CVE-2025-63807 UPD | 7.3 | 9.8 | 0.0049 | good |
CVE-2025-64310 UPD | 7.3 | 9.8 | 0.0046 | good |
CVE-2026-24436 | 7.3 | 9.8 | 0.0042 | good |