Compliance Node Overview
MITRE CAPEC-16 (Dictionary-based Password Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker tries each of the words in a dictionary as passwords to gain access to the system via some user's account. If the password chosen by the user was a word within the dictionary, this attack will be successful (in the absence of other mitigations). This is a specific instance of the password brute forcing attack pattern. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-521, CWE-262, CWE-263, CWE-654, and others.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/16.html
SHA-256 integrity: c6c66d4d0709ef51488443bc091877ef26f1666ebb4ecd07ba59d2c65595a809
Primary Citations — 10 traced to source
- MITRE CAPEC-16: Dictionary-based Password Attack (https://capec.mitre.org/data/definitions/16.html)
- CWE-521: underlying weakness (http://cwe.mitre.org/data/definitions/521.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.