Detailedlikelihood: Mediumseverity: HighDraft
CAPEC-16Dictionary-based Password Attack
Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
High
Description
Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-521, CWE-262, CWE-263, CWE-654, CWE-307 (and 2 more). Related CAPEC patterns: [object Object], [object Object], [object Object], [object Object] (and 2 more).
Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-521, CWE-262, CWE-263, CWE-654, CWE-307 (and 2 more). Related CAPEC patterns: [object Object], [object Object], [object Object], [object Object] (and 2 more).
Related weaknesses· 7
Related attack patterns· 6
Exploits7
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use of Single-factor Authenticationcwe-308 | 100% | live |
| Weakness | Not Using Password Agingcwe-262 | 100% | live |
| Weakness | Reliance on a Single Factor in a Security Decisioncwe-654 | 100% | live |
| Weakness | Weak Password Requirementscwe-521 | 100% | live |
| Weakness | Improper Restriction of Excessive Authentication Attemptscwe-307 | 100% | live |
| Weakness | Password Aging with Long Expirationcwe-263 | 100% | live |
| Weakness | Use of Password System for Primary Authenticationcwe-309 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.