Cyber Resilience

CWE · MITRE source

CWE-15External Control of System or Configuration Setting

Abstraction: Base · CVEs in our corpus: 75

One or more system settings or configuration elements can be externally controlled by a user.

Allowing external control of system settings can disrupt service or cause an application to behave in unexpected, and potentially malicious ways.

Last updated: 21 August 2026 14:15 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 13 mapping(s) from 2 framework(s): CAPEC 8 (mostly) · ATT&CK 5 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A02:2025 Security Misconfiguration.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • CM-1 Policy and Procedures
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-4 Impact Analyses
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 4 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (9)AI-assisted

Showing the 5 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
CM-1Policy and ProceduresCMThe policy and procedures establish internal controls and change management for system configuration settings, reducing the feasibility of external unauthorized modifications.
CM-2Baseline ConfigurationCMBaseline configuration under change control directly prevents unauthorized external modification of system or configuration settings.
CM-3Configuration Change ControlCMRequires approval, documentation, and security impact review of all configuration changes, directly preventing unauthorized external control of system settings.
RA-5Vulnerability Monitoring and ScanningRAVulnerability scanners directly detect externally controllable or misconfigured settings using standardized checklists.
SI-22Information DiversitySIProvides fallback sources for configuration or settings when the primary is externally corrupted or controlled.
Show 4 more broadly-applicable controls
CM-4Impact AnalysesCMImpact analysis of configuration changes reduces the risk of deploying settings that permit unauthorized external control.
CM-5Access Restrictions for ChangeCMRestricting changes to system and configuration settings prevents external entities from controlling those settings without approval.
CM-6Configuration SettingsCMEstablishing, implementing, approving deviations from, and monitoring configuration settings directly prevents external or unauthorized control of system settings.
CM-9Configuration Management PlanCMThe plan defines processes for identifying and managing configuration items, preventing external unauthorized control of system settings.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-41176 8.99.80.32712026-04-23
CVE-2024-39280 8.09.10.34172025-01-14
CVE-2026-45087 7.710.00.01472026-05-27
CVE-2024-38666 7.69.10.18882025-01-14
CVE-2024-4326 7.59.80.00972024-05-16
CVE-2023-50252 7.48.30.23902023-12-12
CVE-2024-51544 7.38.20.13522024-12-05
CVE-2026-22708 7.39.80.00562026-01-14
CVE-2021-38453 7.19.10.01062021-10-22
CVE-2024-10979 7.18.80.04392024-11-14
CVE-2026-44774 7.09.90.00472026-05-15
CVE-2024-39602 6.89.10.02312025-01-14
CVE-2021-27406 6.78.80.01002022-10-14
CVE-2024-39788 6.79.10.01512025-01-14
CVE-2024-39790 6.79.10.01512025-01-14
CVE-2024-39793 6.79.10.01512025-01-14
CVE-2024-39795 6.79.10.01512025-01-14
CVE-2024-39798 6.79.10.01862025-01-14
CVE-2024-39799 6.79.10.01302025-01-14
CVE-2024-39800 6.79.10.01862025-01-14
CVE-2023-46248 6.69.00.01092023-10-31
CVE-2024-39789 6.69.10.01062025-01-14
CVE-2024-39794 6.69.10.01062025-01-14
CVE-2023-32349 6.28.00.00982023-05-22
CVE-2024-51543 6.28.20.00342024-12-05