logo

Database

Description

The application's credential policy does not enforce parameters sufficient to resist guessing attacks.

Impact

Obtain valid credentials through brute-force, dictionary, or credential-stuffing attacks.

Recommendation

- Require passphrases of at least four words or passwords of at least 20 characters. - Reject credentials found in known breach datasets at creation and change time. - Generate temporary credentials with entropy at least equal to that of standard passwords, and force expiry after first use or within a short window (e.g., 15 minutes). - Do not enforce arbitrary periodic expiration without evidence of compromise: per NIST SP 800-63B, mandatory rotation leads users to choose weaker, predictable passwords. Enforce expiration only upon detected compromise.

Threat

Anonymous user from the Internet.

Expected Remediation Time

⏱️ 30 minutes.