BaseDraft

CWE-262Not Using Password Aging

Category: auth

Description

The product does not have a mechanism in place for managing password aging.

Common consequences· 1

  • Access Control — Gain Privileges or Assume Identity
    As passwords age, the probability that they are compromised grows.

Potential mitigations· 2

  • [Architecture and Design]As part of a product's design, require users to change their passwords regularly and avoid reusing previous passwords.
  • [Implementation]Developers might disable clipboard paste operations into password fields as a way to discourage users from pasting a password into a clipboard. However, this might encourage users to choose less-secure passwords that are easier to type, and it can reduce the usability of password managers [REF-1294].

Related CAPEC attack patterns· 12

CAPEC-16CAPEC-49CAPEC-509CAPEC-55CAPEC-555CAPEC-560CAPEC-561CAPEC-565CAPEC-600CAPEC-652CAPEC-653CAPEC-70

References

  1. https://cwe.mitre.org/data/definitions/262.html

Exploits (incoming)12

TypeTargetConfidenceTier
AttackPatternRemote Services with Stolen Credentialscapec-555100%live
AttackPatternDictionary-based Password Attackcapec-16100%live
AttackPatternUse of Known Operating System Credentialscapec-653100%live
AttackPatternRainbow Table Password Crackingcapec-55100%live
AttackPatternCredential Stuffingcapec-600100%live
AttackPatternWindows Admin Shares with Stolen Credentialscapec-561100%live
AttackPatternUse of Known Domain Credentialscapec-560100%live
AttackPatternPassword Sprayingcapec-565100%live
AttackPatternTry Common or Default Usernames and Passwordscapec-70100%live
AttackPatternKerberoastingcapec-509100%live
AttackPatternPassword Brute Forcingcapec-49100%live
AttackPatternUse of Known Kerberos Credentialscapec-652100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Password Aging with Long Expiration
CWE
Weak Password Requirements
CWE
Missing Password Field Masking
CWE
Weak Password Recovery Mechanism for Forgotten Password
CWE
Missing Authentication for Critical Function
CWE
Weak Authentication
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.