7
Authentication Failures
High
Failures in user identity confirmation, authentication, and session management.
Example 1

Weak or predictable passwords

Example 2

Sessions that don't expire

Example 3

Multi-factor authentication not implemented