Minimum password length insufficient

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: pwlen

Platforms: Windows NT
Description:

The allowable minimum password length is less than the value specified in the current policy. In general, passwords shorter than seven characters are especially susceptible to a brute force attack.

Remedy:

Set the minimum password length so that it equals or exceeds the value in the current policy:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. From the Policies menu, select Account to display the Account Policy dialog box.
  3. Set the minimum password length to at least the number of characters specified by the current policy.
  4. Click OK.
References:

X-Force Logo
Know Your Risks