NIST 800-53 r5 · Controls catalogue · Family IA
IA-11Re-authentication
Require users to re-authenticate when {{ insert: param, ia-11_odp }}.
Last updated: 21 August 2026 14:15 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (7)
- T1110 Brute Force Credential Access
- T1110.001 Password Guessing Credential Access
- T1110.002 Password Cracking Credential Access
- T1110.003 Password Spraying Credential Access
- T1110.004 Credential Stuffing Credential Access
- T1556.006 Multi-Factor Authentication Defense Impairment, Persistence, Credential Access
- T1556.007 Hybrid Identity Defense Impairment, Persistence, Credential Access
Weaknesses this control addresses (4)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-352 | Cross-Site Request Forgery (CSRF) | 10,700+ | Requiring user re-entry of credentials for sensitive actions prevents automated forgery of requests without active user participation. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Re-authentication enforces fresh credential validation for critical functions or operations as defined by the organization parameter. |
CWE-613 | Insufficient Session Expiration | 600+ | Re-authentication after inactivity or time-based triggers prevents indefinite use of potentially hijacked or stale sessions. |
CWE-384 | Session Fixation | 400+ | Re-authentication typically forces issuance of a new session, limiting the window for exploitation of a previously fixed session identifier. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-20419 UPD | 10.0 | 10.0 | 0.8064 | good |
CVE-2024-48887 UPD | 8.4 | 9.8 | 0.1483 | good |
CVE-2025-4322 UPD | 8.4 | 9.8 | 0.1565 | good |
CVE-2024-33699 UPD | 7.9 | 9.9 | 0.1064 | good |
CVE-2024-12824 UPD | 7.7 | 9.8 | 0.0230 | good |
CVE-2024-13375 UPD | 7.6 | 9.8 | 0.0144 | good |
CVE-2025-10159 UPD | 7.5 | 9.8 | 0.0088 | good |
CVE-2025-2253 UPD | 7.4 | 9.8 | 0.0080 | good |
CVE-2025-63362 UPD | 7.4 | 9.8 | 0.0059 | good |
CVE-2024-37998 UPD | 7.3 | 9.8 | 0.0045 | good |
CVE-2024-26520 UPD | 7.3 | 9.8 | 0.0051 | good |
CVE-2024-12860 | 7.3 | 9.8 | 0.0048 | good |
CVE-2025-3603 UPD | 7.3 | 9.8 | 0.0053 | good |
CVE-2025-4558 UPD | 7.3 | 9.8 | 0.0051 | good |
CVE-2025-4606 UPD | 7.3 | 9.8 | 0.0056 | good |
CVE-2025-9286 UPD | 7.3 | 9.8 | 0.0044 | good |
CVE-2026-15964 UPD | 7.3 | 9.8 | 0.0049 | good |
CVE-2024-12827 UPD | 7.2 | 9.8 | 0.0035 | good |
CVE-2026-12692 | 7.2 | 9.8 | 0.0035 | good |
CVE-2025-1107 UPD | 7.0 | 9.9 | 0.0041 | good |
CVE-2026-5386 UPD | 6.9 | 9.1 | 0.0062 | good |
CVE-2026-30458 UPD | 6.8 | 9.1 | 0.0036 | good |
CVE-2024-9431 UPD | 6.6 | 8.8 | 0.0061 | good |
CVE-2025-5482 UPD | 6.6 | 8.8 | 0.0050 | good |
CVE-2026-24443 | 6.6 | 8.8 | 0.0046 | good |