BaseIncomplete
CWE-836Use of Password Hash Instead of Password for Authentication
Category: auth
Description
The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.
Common consequences· 1
- Access Control — Bypass Protection Mechanism, Gain Privileges or Assume IdentityAn attacker could bypass the authentication routine without knowing the original password.
Related CAPEC attack patterns· 2
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Use of Known Kerberos Credentialscapec-652 | 100% | live |
| AttackPattern | Use of Captured Hashes (Pass The Hash)capec-644 | 100% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-62618cve-2025-62618 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.