info: name: Linux Password Maximum Usage Period Not Configured author: songyaeji severity: medium description:> If password expiration is not enforced, compromised passwords may remain valid indefinitely, posing a security risk. This template checks whether PASS_MAX_DAYS is configured properly (≤ 90) and whether individual user shadow entries exceed acceptable limits. reference: - https://isms.kisa.or.kr/main/csap/notice/ - Cloud Vulnerability Assessment Guide(2024) by KISA tags: linux,local,misconfiguration,password,compliance metadata: verified:true os: linux max-request:2 classification: cwe-id: CWE-284 cvss-metrics: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L cvss-score:4.6