Cyber Resilience

CWE · MITRE source

CWE-1188Initialization of a Resource with an Insecure Default

Abstraction: Base · CVEs in our corpus: 321

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Last updated: 22 August 2026 20:22 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: full · 7 mapping(s) from 7 framework(s): STIG rhel 7 1 (full) · STIG windows server 2019 1 (mostly) · STIG ubuntu 22 04 1 (mostly) · STIG ubuntu 24 04 1 (mostly) · CAPEC 1 (partial) · STIG windows server 2016 1 (partial) · STIG oracle linux 8 1 (partial)

See the full cumulative-coverage rollup →

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • CM-1 Policy and Procedures
  • CM-2 Baseline Configuration
  • CM-7 Least Functionality
  • SA-16 Developer-provided Training
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 13 hardening rules · 7 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V14.3.2
  • V6.3.2
  • V11.3.1
  • V13.2.3

NIST 800-53 r5 controls that address this weakness (10)AI-assisted

Control Title Family Why it addresses this CWE
CM-1Policy and ProceduresCMRequires documented secure initialization practices and avoidance of insecure defaults in configuration baselines.
CM-2Baseline ConfigurationCMReviewing and updating baseline when components are installed or upgraded prevents initialization with insecure defaults.
CM-7Least FunctionalityCMRequiring explicit configuration to minimal functionality overrides insecure defaults that would otherwise enable excess capabilities.
SA-16Developer-provided TrainingSAInstruction on secure initialization of security controls prevents leaving resources with insecure defaults after installation.
SA-4Acquisition ProcessSAMandating secure configuration and initialization requirements in the acquisition process prevents delivery of products that initialize resources with insecure defaults.
SA-5System DocumentationSASecure configuration and installation documentation prevents initialization of resources with insecure defaults.
PL-11Baseline TailoringPLTailoring replaces or augments insecure default initializations with system-specific values and compensating controls before deployment.
PL-9Central ManagementPLCentral configuration overrides or replaces insecure default initializations that would otherwise be left unchanged on each system.
PM-30Supply Chain Risk Management StrategyPMSCRM practices during acquisition and configuration management address insecure default initializations shipped by vendors.
RA-5Vulnerability Monitoring and ScanningRAScans detect resources initialized with insecure defaults that create exploitable conditions.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-11532 9.99.80.77482020-05-08
CVE-2020-13927 KEV 9.99.80.99782020-11-10
CVE-2022-24706 KEV 9.99.80.92412022-04-26
CVE-2023-6448 KEV 9.99.80.02092023-12-05
CVE-2023-27524 KEV 8.98.90.97402023-04-24
CVE-2020-14011 8.89.80.29472020-06-15
CVE-2018-8014 8.69.80.21722018-05-16
CVE-2018-16752 8.48.80.42662018-09-20
CVE-2021-38759 8.49.80.15672021-12-07
CVE-2017-5178 8.39.80.13632017-03-08
CVE-2021-35336 8.29.80.10112021-07-01
CVE-2019-5367 8.19.80.08042019-06-05
CVE-2017-12739 8.09.80.05652017-11-15
CVE-2026-476688.010.00.04342026-07-23
CVE-2017-3834 7.99.80.04462017-04-06
CVE-2018-10251 7.99.80.04492018-05-04
CVE-2018-15350 7.99.80.04692018-08-17
CVE-2018-19275 7.99.80.04612019-04-02
CVE-2019-7252 7.99.80.04852019-07-02
CVE-2026-416797.910.00.02952026-04-23
CVE-2026-672087.99.80.04232026-07-30
CVE-2017-7964 7.810.00.02502017-04-19
CVE-2018-5770 7.89.80.02742018-03-20
CVE-2019-5490 7.89.80.03492019-03-21
CVE-2019-1804 7.89.80.03482019-05-03