Cyber Resilience

CWE · MITRE source

CWE-1023Incomplete Comparison with Missing Factors

Abstraction: Class · CVEs in our corpus: 13

The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.AA-03
  • PR.AA-05
  • AC-3 Access Enforcement
  • AC-24 Access Control Decisions
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V6.3.4
  • V6.3.5
  • V6.1.3
  • V6.5.7

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-7473 KEV 7.55.80.01112026-06-05
CVE-2026-4599 6.99.10.00482026-03-23
CVE-2026-242555.87.50.00382026-08-04
CVE-2026-47485.77.50.00252026-04-01
CVE-2021-23146 5.67.10.00852021-11-18
CVE-2025-62000 5.27.10.00212025-12-18
CVE-2026-53839 5.06.50.00272026-06-12
CVE-2025-55333 4.96.10.00822025-10-14
CVE-2026-538594.96.50.00212026-06-16
CVE-2026-487614.56.10.00272026-07-14
CVE-2025-46722 3.54.20.00292025-05-29
CVE-2024-5528 3.23.50.00402025-02-05
CVE-2026-48587 2.83.10.00352026-06-03