NIST 800-53 r5 · Controls catalogue · Family IA
IA-3Device Identification and Authentication
Uniquely identify and authenticate {{ insert: param, ia-03_odp.01 }} before establishing a {{ insert: param, ia-03_odp.02 }} connection.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (8)
- T1530 Data from Cloud Storage Collection
- T1537 Transfer Data to Cloud Account Exfiltration
- T1552 Unsecured Credentials Credential Access
- T1552.005 Cloud Instance Metadata API Credential Access
- T1602 Data from Configuration Repository Collection
- T1602.001 SNMP (MIB Dump) Collection
- T1602.002 Network Device Configuration Dump Collection
- T1621 Multi-Factor Authentication Request Generation Credential Access
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-287 | Improper Authentication | 5,200+ | Enforces unique device identification and authentication before any connection is established, directly mitigating improper authentication weaknesses. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Requires authentication of devices prior to connection, preventing exploitation of missing authentication for critical network functions. |
CWE-290 | Authentication Bypass by Spoofing | 700+ | Unique device authentication makes successful spoofing of device identity substantially more difficult to achieve. |
CWE-300 | Channel Accessible by Non-Endpoint | 55 | Ensures only authenticated endpoints can access the communication channel, blocking unauthorized non-endpoint access. |
CWE-291 | Reliance on IP Address for Authentication | 10 | Mandates proper device-level authentication instead of weaker identifiers such as IP addresses that are easily forged. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-61932 KEV | 9.9 | 9.8 | 0.0263 | good |
CVE-2026-1709 UPD | 7.7 | 9.4 | 0.0543 | good |
CVE-2026-1490 UPD | 7.5 | 9.8 | 0.0116 | good |
CVE-2024-40515 UPD | 7.4 | 9.8 | 0.0066 | good |
CVE-2024-38886 UPD | 7.4 | 9.8 | 0.0064 | good |
CVE-2024-41889 UPD | 7.4 | 9.8 | 0.0068 | good |
CVE-2023-28078 UPD | 7.0 | 9.1 | 0.0089 | good |
CVE-2024-24974 UPD | 6.7 | 7.5 | 0.0976 | good |
CVE-2026-2611 UPD | 6.7 | 9.6 | 0.0038 | good |
CVE-2023-52235 UPD | 6.6 | 8.8 | 0.0052 | good |
CVE-2025-59159 UPD | 6.6 | 9.6 | 0.0024 | good |
CVE-2026-34205 | 6.6 | 9.6 | 0.0026 | good |
CVE-2024-40516 UPD | 6.5 | 8.8 | 0.0033 | good |
CVE-2025-20261 UPD | 6.5 | 8.8 | 0.0040 | good |
CVE-2026-33875 | 6.5 | 9.3 | 0.0027 | good |
CVE-2026-35643 | 6.5 | 8.8 | 0.0037 | good |
CVE-2026-48745 | 6.5 | 9.3 | 0.0032 | good |
CVE-2025-61939 UPD | 6.4 | 8.8 | 0.0024 | good |
CVE-2024-26131 UPD | 6.3 | 8.4 | 0.0047 | good |
CVE-2024-47490 UPD | 6.3 | 8.2 | 0.0058 | good |
CVE-2024-31206 UPD | 6.2 | 8.2 | 0.0033 | good |
CVE-2024-47519 UPD | 6.2 | 8.3 | 0.0034 | good |
CVE-2025-23222 UPD | 6.2 | 8.4 | 0.0024 | good |
CVE-2026-45361 UPD | 6.2 | 8.1 | 0.0059 | good |
CVE-2023-31004 UPD | 6.1 | 8.3 | 0.0099 | good |