Cyber Resilience

CWE · MITRE source

CWE-307Improper Restriction of Excessive Authentication Attempts

Abstraction: Base · CVEs in our corpus: 616

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Last updated: 11 August 2026 23:24 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 9 mapping(s) from 3 framework(s): CAPEC 6 (partial) · STIG rhel 7 2 (mostly) · ATT&CK 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A07:2025 Authentication Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • AC-7 Unsuccessful Logon Attempts
  • IA-10 Adaptive Authentication
  • PR.AA-03
  • PR.PS-04
Detect
Catch it (CSF Detect / Respond)
  • DE.CM-03
Harden
Shrink the surface (DISA STIG)
  • 2 hardening rules · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (2)AI-assisted

Control Title Family Why it addresses this CWE
AC-7Unsuccessful Logon AttemptsACThis control directly enforces limits on consecutive invalid logon attempts and automatic response (e.g., lockout) to prevent brute-force exploitation of authentication mechanisms.
IA-10Adaptive AuthenticationIASpecific conditions can include excessive failed attempts, triggering stronger authentication that restricts brute-force exploitation.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-17240 9.19.80.39602019-10-06
CVE-2020-15906 8.89.80.27362020-10-22
CVE-2016-9361 8.59.80.19862017-02-13
CVE-2024-39225 8.49.80.14532024-08-06
CVE-2023-27100 8.29.80.09842023-03-22
CVE-2001-1339 8.19.80.07492001-05-24
CVE-2001-1291 8.19.80.08902001-07-12
CVE-2021-41435 8.09.80.05992021-11-19
CVE-2017-7898 7.99.80.05152017-06-30
CVE-2020-7995 7.99.80.04542020-01-26
CVE-2020-35590 7.99.80.04352020-12-21
CVE-1999-1324 7.89.80.03091999-12-31
CVE-2016-9366 7.89.80.03082017-02-13
CVE-2018-5469 7.89.80.02892018-03-06
CVE-2019-6524 7.89.80.02732019-03-05
CVE-2021-27514 7.89.80.03552021-02-22
CVE-2001-0395 7.79.80.01912001-07-02
CVE-2016-9124 7.79.80.02232017-03-28
CVE-2017-15887 7.79.80.01942017-11-07
CVE-2018-1475 7.79.80.02212018-04-27
CVE-2019-4336 7.79.80.02012019-07-01
CVE-2019-3766 7.79.80.01952019-09-27
CVE-2019-12941 7.79.80.02382019-10-14
CVE-2019-16670 7.79.80.01982019-12-06
CVE-2013-4441 7.79.80.02022020-01-27