CWE · MITRE source
CWE-1188Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
Last updated: 22 August 2026 20:22 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: full · 7 mapping(s) from 7 framework(s): STIG rhel 7 1 (full) · STIG windows server 2019 1 (mostly) · STIG ubuntu 22 04 1 (mostly) · STIG ubuntu 24 04 1 (mostly) · CAPEC 1 (partial) · STIG windows server 2016 1 (partial) · STIG oracle linux 8 1 (partial)
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 13 hardening rules · 7 OS baselines
V14.3.2V6.3.2V11.3.1V13.2.3
NIST 800-53 r5 controls that address this weakness (10)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
CM-1 | Policy and Procedures | CM | Requires documented secure initialization practices and avoidance of insecure defaults in configuration baselines. |
CM-2 | Baseline Configuration | CM | Reviewing and updating baseline when components are installed or upgraded prevents initialization with insecure defaults. |
CM-7 | Least Functionality | CM | Requiring explicit configuration to minimal functionality overrides insecure defaults that would otherwise enable excess capabilities. |
SA-16 | Developer-provided Training | SA | Instruction on secure initialization of security controls prevents leaving resources with insecure defaults after installation. |
SA-4 | Acquisition Process | SA | Mandating secure configuration and initialization requirements in the acquisition process prevents delivery of products that initialize resources with insecure defaults. |
SA-5 | System Documentation | SA | Secure configuration and installation documentation prevents initialization of resources with insecure defaults. |
PL-11 | Baseline Tailoring | PL | Tailoring replaces or augments insecure default initializations with system-specific values and compensating controls before deployment. |
PL-9 | Central Management | PL | Central configuration overrides or replaces insecure default initializations that would otherwise be left unchanged on each system. |
PM-30 | Supply Chain Risk Management Strategy | PM | SCRM practices during acquisition and configuration management address insecure default initializations shipped by vendors. |
RA-5 | Vulnerability Monitoring and Scanning | RA | Scans detect resources initialized with insecure defaults that create exploitable conditions. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2020-11532 UPD | 9.9 | 9.8 | 0.7748 | 2020-05-08 |
CVE-2020-13927 KEV UPD | 9.9 | 9.8 | 0.9978 | 2020-11-10 |
CVE-2022-24706 KEV UPD | 9.9 | 9.8 | 0.9241 | 2022-04-26 |
CVE-2023-6448 KEV UPD | 9.9 | 9.8 | 0.0209 | 2023-12-05 |
CVE-2023-27524 KEV UPD | 8.9 | 8.9 | 0.9740 | 2023-04-24 |
CVE-2020-14011 UPD | 8.8 | 9.8 | 0.2947 | 2020-06-15 |
CVE-2018-8014 UPD | 8.6 | 9.8 | 0.2172 | 2018-05-16 |
CVE-2018-16752 UPD | 8.4 | 8.8 | 0.4266 | 2018-09-20 |
CVE-2021-38759 UPD | 8.4 | 9.8 | 0.1567 | 2021-12-07 |
CVE-2017-5178 UPD | 8.3 | 9.8 | 0.1363 | 2017-03-08 |
CVE-2021-35336 UPD | 8.2 | 9.8 | 0.1011 | 2021-07-01 |
CVE-2019-5367 UPD | 8.1 | 9.8 | 0.0804 | 2019-06-05 |
CVE-2017-12739 UPD | 8.0 | 9.8 | 0.0565 | 2017-11-15 |
CVE-2026-47668 | 8.0 | 10.0 | 0.0434 | 2026-07-23 |
CVE-2017-3834 UPD | 7.9 | 9.8 | 0.0446 | 2017-04-06 |
CVE-2018-10251 UPD | 7.9 | 9.8 | 0.0449 | 2018-05-04 |
CVE-2018-15350 UPD | 7.9 | 9.8 | 0.0469 | 2018-08-17 |
CVE-2018-19275 UPD | 7.9 | 9.8 | 0.0461 | 2019-04-02 |
CVE-2019-7252 UPD | 7.9 | 9.8 | 0.0485 | 2019-07-02 |
CVE-2026-41679 | 7.9 | 10.0 | 0.0295 | 2026-04-23 |
CVE-2026-67208 | 7.9 | 9.8 | 0.0423 | 2026-07-30 |
CVE-2017-7964 UPD | 7.8 | 10.0 | 0.0250 | 2017-04-19 |
CVE-2018-5770 UPD | 7.8 | 9.8 | 0.0274 | 2018-03-20 |
CVE-2019-5490 UPD | 7.8 | 9.8 | 0.0349 | 2019-03-21 |
CVE-2019-1804 UPD | 7.8 | 9.8 | 0.0348 | 2019-05-03 |