CWE-654: Reliance on a Single Factor in a Security Decision

ID CWE-654
Abstraction Base
Structure Simple
Status Draft
Number of CVEs 1
A protection mechanism relies exclusively, or to a large extent, on the evaluation of a single condition or the integrity of a single object or entity in order to make a decision about granting access to restricted resources or functionality.

Modes of Introduction

Phase Note
Architecture and Design
Implementation
Operation

Applicable Platforms

Type Class Name Prevalence
Language Not Language-Specific

Relationships

View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-657 Violation of Secure Design Principles Class Simple Draft
CWE-1000 Research Concepts Draft CWE-693 Protection Mechanism Failure Pillar Simple Draft

Common Attack Pattern Enumeration and Classification (CAPEC)

The Common Attack Pattern Enumeration and Classification (CAPECâ„¢) effort provides a publicly available catalog of common attack patterns that helps users understand how adversaries exploit weaknesses in applications and other cyber-enabled capabilities.

CAPEC at Mitre.org
# ID Name Weaknesses
CAPEC-16 Dictionary-based Password Attack CWE-654
CAPEC-49 Password Brute Forcing CWE-654
CAPEC-55 Rainbow Table Password Cracking CWE-654
CAPEC-70 Try Common or Default Usernames and Passwords CWE-654
CAPEC-274 HTTP Verb Tampering CWE-654
CAPEC-560 Use of Known Domain Credentials CWE-654
CAPEC-565 Password Spraying CWE-654
CAPEC-600 Credential Stuffing CWE-654
CAPEC-652 Use of Known Kerberos Credentials CWE-654
CAPEC-653 Use of Known Operating System Credentials CWE-654

CVEs Published

CVSS Severity

CVSS Severity - By Year

CVSS Base Score

# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...
Loading...