CWE•Base•Draft•1 recent CVE
CWE-262Not Using Password Aging
Description
The product does not have a mechanism in place for managing password aging.
[object Object]
Common consequences
- Access Control→Gain Privileges or Assume IdentityAs passwords age, the probability that they are compromised grows.
Potential mitigations
- Architecture and DesignAs part of a product's design, require users to change their passwords regularly and avoid reusing previous passwords.
- ImplementationDevelopers might disable clipboard paste operations into password fields as a way to discourage users from pasting a password into a clipboard. However, this might encourage users to choose less-secure passwords that are easier to type, and it can reduce the usability of password managers [REF-1294].