Weak credential policy - Temporary passwords
Description
Temporary passwords do not have strong enough security policies.
Impact
Compromise temporary passwords to gain unauthorized access to the application
Recommendation
Set secure temporary passwords by following the recommended best practices.
Threat
Anonymous attacker from the Internet
Expected Remediation Time
⏱️ 30 minutes.
Requirements
130 - Limit password lifespan132 - Passphrases with at least 4 words133 - Passwords with at least 20 characters136 - Force temporary password change137 - Change temporary passwords of third parties139 - Set minimum OTP length332 - Prevent the use of breached passwordsFixes