Standardlikelihood: Mediumseverity: HighDraft
CAPEC-50Password Recovery Exploitation
Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
High
Description
An attacker may take advantage of the application feature to help users recover their forgotten passwords in order to gain access into the system with the same privileges as the original user. Generally password recovery schemes tend to be weak and insecure.
Metadata: standard CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-522, CWE-640. Related CAPEC patterns: [object Object], [object Object], [object Object], [object Object] (and 2 more).
Related weaknesses· 2
Related attack patterns· 6
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Insufficiently Protected Credentialscwe-522 | 100% | live |
| Weakness | Weak Password Recovery Mechanism for Forgotten Passwordcwe-640 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.