info: name: Linux Account Lockout Threshold Not Configured author: songyaeji severity: high description:> The system does not enforce an account lockout threshold. Without this control, repeated login attempts are not restricted, leaving the system vulnerable to brute-force attacks. This template checks whether account lockout settings are configured in PAM modules. reference: - https://isms.kisa.or.kr/main/csap/notice/ - Cloud Vulnerability Assessment Guide(2024) by KISA tags: linux,local,pam,auth,misconfiguration,compliance metadata: verified:true os: linux max-request:3 classification: cwe-id: CWE-307 cvss-metrics: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H cvss-score:5.5