Cyber Resilience

CWE · MITRE source

CWE-346Origin Validation Error

Abstraction: Class · CVEs in our corpus: 730

The product does not properly verify that the source of data or communication is valid.

Last updated: 22 August 2026 07:11 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 15 mapping(s) from 3 framework(s): CAPEC 11 (partial) · STIG oracle linux 8 3 (mostly) · ATT&CK 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A07:2025 Authentication Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-11 Trusted Path
  • SC-20 Secure Name/Address Resolution Service (Authoritative Source)
  • SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
  • SC-23 Session Authenticity
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 3 hardening rules · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (5)AI-assisted

Showing the 4 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
SC-11Trusted PathSCTrusted path establishment enforces validation that the communication originates from and reaches only the intended trusted system components.
SC-20Secure Name/Address Resolution Service (Authoritative Source)SCEnforces validation of the true origin of DNS responses via signatures and chain-of-trust mechanisms.
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)SCEnforces origin validation of name/address data, eliminating reliance on unverified or impersonated DNS sources.
IA-9Service Identification and AuthenticationIARequires unique identification of the service before communications, addressing failures to validate the origin of the interaction.
Show 1 more broadly-applicable controls
SC-23Session AuthenticitySCMandates origin validation so that only legitimate endpoints can continue the authenticated session.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-29711 9.89.80.70312023-06-22
CVE-2015-4495 KEV 9.28.80.68662015-08-08
CVE-2025-34291 KEV 9.28.80.83842025-12-05
CVE-2020-16952 9.18.60.71092020-10-16
CVE-2024-23898 9.08.80.67152024-01-24
CVE-2000-1218 8.09.80.06092000-04-14
CVE-2019-8069 7.99.80.04532019-09-12
CVE-2019-3980 7.99.80.05142019-10-08
CVE-2018-15723 7.89.80.03702018-12-20
CVE-2021-37705 7.810.00.02422021-08-13
CVE-2023-33443 7.89.80.03502023-06-08
CVE-2025-69258 7.89.80.03532026-01-08
CVE-2021-26291 7.79.10.08692021-04-23
CVE-2019-16517 7.69.80.01342020-01-23
CVE-2003-0174 7.59.80.00982003-05-12
CVE-2018-5116 7.59.80.01172018-06-11
CVE-2018-5409 7.59.80.01082019-05-08
CVE-2019-15020 7.59.80.00892019-10-09
CVE-2020-26527 7.59.80.00912020-10-02
CVE-2017-6519 7.49.10.03242017-05-01
CVE-2017-20146 7.49.80.00702022-12-27
CVE-2023-29728 7.49.80.00582023-05-30
CVE-2017-13274 7.39.80.00502018-04-04
CVE-2019-4640 7.39.80.00522020-02-19
CVE-2023-25366 7.39.80.00412023-06-16