035 – Weak credential policy
Description
The systems credential policy is not compliant with security regulations.
Impact
Increase the chances of getting valid credentials using brute force or dictionary attacks.
Recommendation
Establish a policy for creation of credentials that uses phrases, not word based passwords.
Threat
Anonymous user from the Internet.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: N
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): L
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X