CWE-262

Not Using Password Aging

High

Description

The product does not have a mechanism in place for managing password aging.

Potential Impact

How to Fix

Architecture and Design

As part of a product's design, require users to change their passwords regularly and avoid reusing previous passwords.

Implementation

Developers might disable clipboard paste operations into password fields as a way to discourage users from pasting a password into a clipboard. However, this might encourage users to choose less-secure passwords that are easier to type, and it can reduce the usability of password managers [REF-1294].

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-262 vulnerabilities in your codebase.

Get Security Assessment