CWE-836 - CERT CVE

CWE-836 - Use of Password Hash Instead of Password for Authentication

The software records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.

CAPEC ID Naziv
CAPEC-644 Use of Captured Hashes (Pass The Hash)
CAPEC-652 Use of Known Kerberos Credentials