CWE-521
Overview
- CWE ID
- 521
- CWE Name
- Weak Password Requirements
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Draft
Description
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Extended Description
Authentication mechanisms often rely on a memorized secret (also known as a password) to provide an assertion of identity for a user of a system. It is therefore important that this password be of sufficient complexity and impractical for an adversary to