VYPR

CWE-262

Not Using Password Aging

BaseDraftLikelihood: Low

Description

The product does not have a mechanism in place for managing password aging.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653 · CAPEC-70

CVEs mapped to this weakness (6)

  • CVE-2022-22767HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.00

    Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s)…

  • CVE-2026-50101HigJun 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any…

  • CVE-2025-60010MedOct 9, 2025
    risk 0.35cvss 5.4epss 0.00

    A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Affected devices allow logins by users for whom the RADIUS…

  • CVE-2023-2022MedAug 2, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even…

  • CVE-2025-58435MedSep 9, 2025
    risk 0.20cvss epss 0.00

    Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an…

  • CVE-2023-1555LowSep 1, 2023
    risk 0.18cvss 2.7epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.