Standardlikelihood: Mediumseverity: HighDraft
CAPEC-49Password Brute Forcing
Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
High
Description
An adversary tries every possible value for a password until they succeed. A brute force attack, if feasible computationally, will always be successful because it will essentially go through all possible passwords given the alphabet used (lower case letters, upper case letters, numbers, symbols, etc.) and the maximum length of the password.
Related weaknesses· 8
MITRE ATT&CK crosswalk· 1
Related attack patterns· 6
Exploits8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use of Single-factor Authenticationcwe-308 | 100% | live |
| Weakness | Storing Passwords in a Recoverable Formatcwe-257 | 100% | live |
| Weakness | Weak Password Requirementscwe-521 | 100% | live |
| Weakness | Improper Restriction of Excessive Authentication Attemptscwe-307 | 100% | live |
| Weakness | Password Aging with Long Expirationcwe-263 | 100% | live |
| Weakness | Reliance on a Single Factor in a Security Decisioncwe-654 | 100% | live |
| Weakness | Not Using Password Agingcwe-262 | 100% | live |
| Weakness | Use of Password System for Primary Authenticationcwe-309 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Password Guessingt1110.001 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.