CWE · MITRE source
CWE-307Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Last updated: 11 August 2026 23:24 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 9 mapping(s) from 3 framework(s): CAPEC 6 (partial) · STIG rhel 7 2 (mostly) · ATT&CK 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A07:2025 Authentication Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (2)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
AC-7 | Unsuccessful Logon Attempts | AC | This control directly enforces limits on consecutive invalid logon attempts and automatic response (e.g., lockout) to prevent brute-force exploitation of authentication mechanisms. |
IA-10 | Adaptive Authentication | IA | Specific conditions can include excessive failed attempts, triggering stronger authentication that restricts brute-force exploitation. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2019-17240 UPD | 9.1 | 9.8 | 0.3960 | 2019-10-06 |
CVE-2020-15906 UPD | 8.8 | 9.8 | 0.2736 | 2020-10-22 |
CVE-2016-9361 UPD | 8.5 | 9.8 | 0.1986 | 2017-02-13 |
CVE-2024-39225 UPD | 8.4 | 9.8 | 0.1453 | 2024-08-06 |
CVE-2023-27100 UPD | 8.2 | 9.8 | 0.0984 | 2023-03-22 |
CVE-2001-1339 UPD | 8.1 | 9.8 | 0.0749 | 2001-05-24 |
CVE-2001-1291 UPD | 8.1 | 9.8 | 0.0890 | 2001-07-12 |
CVE-2021-41435 UPD | 8.0 | 9.8 | 0.0599 | 2021-11-19 |
CVE-2017-7898 UPD | 7.9 | 9.8 | 0.0515 | 2017-06-30 |
CVE-2020-7995 UPD | 7.9 | 9.8 | 0.0454 | 2020-01-26 |
CVE-2020-35590 UPD | 7.9 | 9.8 | 0.0435 | 2020-12-21 |
CVE-1999-1324 UPD | 7.8 | 9.8 | 0.0309 | 1999-12-31 |
CVE-2016-9366 UPD | 7.8 | 9.8 | 0.0308 | 2017-02-13 |
CVE-2018-5469 UPD | 7.8 | 9.8 | 0.0289 | 2018-03-06 |
CVE-2019-6524 UPD | 7.8 | 9.8 | 0.0273 | 2019-03-05 |
CVE-2021-27514 UPD | 7.8 | 9.8 | 0.0355 | 2021-02-22 |
CVE-2001-0395 UPD | 7.7 | 9.8 | 0.0191 | 2001-07-02 |
CVE-2016-9124 UPD | 7.7 | 9.8 | 0.0223 | 2017-03-28 |
CVE-2017-15887 UPD | 7.7 | 9.8 | 0.0194 | 2017-11-07 |
CVE-2018-1475 UPD | 7.7 | 9.8 | 0.0221 | 2018-04-27 |
CVE-2019-4336 UPD | 7.7 | 9.8 | 0.0201 | 2019-07-01 |
CVE-2019-3766 UPD | 7.7 | 9.8 | 0.0195 | 2019-09-27 |
CVE-2019-12941 UPD | 7.7 | 9.8 | 0.0238 | 2019-10-14 |
CVE-2019-16670 UPD | 7.7 | 9.8 | 0.0198 | 2019-12-06 |
CVE-2013-4441 UPD | 7.7 | 9.8 | 0.0202 | 2020-01-27 |