CAPEC-600: Credential Stuffing

An adversary tries known username/password combinations against different systems, applications, or services to gain additional authenticated access. Credential Stuffing attacks rely upon the fact that many users leverage the same username/password combination for multiple systems, applications, and services.

Severity
High
Likelihood
High
5
/ 100
low-risk
Active Threat 5/50 · Minimal
Exploit Availability 0/50 · Minimal