info: name: Linux Password Complexity Not Enforced author: songyaeji severity: high description:> Password complexity requirements are not enforced on this system. This allows weak passwords, making user accounts more susceptible to brute-force and dictionary attacks. reference: - https://isms.kisa.or.kr/main/csap/notice/ - Cloud Vulnerability Assessment Guide(2024) by KISA tags: linux,local,configuration,auth,weak-password,compliance metadata: verified:true os: linux max-request:2 classification: cvss-metrics: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H cvss-score:7.8 cwe-id: CWE-521