King of Spoofing II
Your system ships with a default admin password and doesn’t force a change.
Threat |
|
New users are created with a default password that is always the same and they aren’t obliged to change it on first login. This results in many new users using the same password if not required to be changed on a regular schedule, potentially indefinitely. |
|
CAPEC |
CAPEC-70 - Try Common or Default Usernames and Passwords |
ASVS |
2.5.4 - Ensure shared or default accounts have been removed 2.3.1 - Ensure forced change of password on first login |
CWE |
CWE-1392 - Use of Default Credentials CWE-1393 - Use of Default Password |
Mitigations... |