VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (264)

page 14 of 14
  • CVE-2022-1236MedApr 5, 2022
    risk 0.00cvss 6.5epss 0.01

    Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.

  • CVE-2021-25923HigJun 24, 2021
    risk 0.00cvss 8.1epss 0.01

    In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.

  • CVE-2020-8296MedMar 3, 2021
    risk 0.00cvss 6.7epss 0.01

    Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.

  • CVE-2020-8632MedFeb 5, 2020
    risk 0.00cvss 5.5epss 0.00

    In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.