Compliance Node Overview
MITRE CAPEC-49 (Password Brute Forcing) is an attack pattern in which an adversary tries every possible value for a password until they succeed. The CAPEC page identifies three prerequisites: adversary needs username; system uses password-based single-factor authentication; application does not have password throttling. Likelihood of attack: Medium. Typical severity: High. Maps to MITRE ATT&CK T1110.001 (Brute Force: Password Guessing) and CWE-521, CWE-307, CWE-308. Compliance: PCI DSS v4.0 Req 8.3, NIST SP 800-63B AAL2/3, NIS2 Article 21(2)(j), HIPAA Security Rule.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/49.html
SHA-256 integrity: fc6ff3b933a852a55bccf8af52e3a22b9b23b8e50537d533cb3d8349a1a3a480
Primary Citations — 8 traced to source
- MITRE CAPEC-49: Password Brute Forcing (https://capec.mitre.org/data/definitions/49.html)
- CWE-521: Weak Password Requirements
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.