Common Weakness Enumeration

    CWE Definition / CWE-307

    CWE-307: Improper Restriction of Excessive Authentication Attempts

    The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-1390: Weak Authentication

    CWE-287: Improper Authentication

    CWE-799: Improper Control of Interaction Frequency