CWE-309: Use of Password System for Primary Authentication

low-risk

The use of password systems as the primary means of authentication may be subject to several flaws or shortcomings, each reducing the effectiveness of the mechanism.

Abstraction: Base

Common Consequences

Access Control Bypass Protection Mechanism

Real-World Examples (1)

CVE CVSS EPSS KEV
CVE-2024-45675 8.4 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal