9. of Spoofing II
An attacker who gets a password can reuse it (use stronger authenticators).
Threat |
|
If the user has reused their password and a service provider has not been protecting their data correctly, their password may have been stolen, which they can then reuse because you don’t require additional factors (token, biometric, FIDO2). |
|
CAPEC |
CAPEC-560 - Use of Known Domain Credentials |
ASVS |
2.2.6 - Ensure replay attack protections are in place and working correctly 2.2.7 - Ensure user-in-the-loop with automation protection controls |
CWE |
CWE-308 - Use of Single-Factor Authentication |
Mitigations |
|
... |