logo

035 Weak credential policy


Description

The systems credential policy is not compliant with security regulations.


Impact

Increase the chances of getting valid credentials using brute force or dictionary attacks.


Recommendation

Establish a policy for creation of credentials that uses phrases, not word based passwords.


Threat

Anonymous user from the Internet.


Expected Remediation Time

30 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: N
  • User interaction: N
  • Confidentiality (VC): L
  • Integrity (VI): N
  • Availability (VA): N
  • Confidentiality (SC): L
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/07