CWE · MITRE source
CWE-521Weak Password Requirements
The product does not require that users should have strong passwords.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 15 mapping(s) from 3 framework(s): CAPEC 9 (partial) · ATT&CK 4 (partial) · STIG rhel 7 2 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A07:2025 Authentication Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 2 hardening rules · 1 OS baseline
V6.2.4V6.2.9V6.2.12V6.4.1
NIST 800-53 r5 controls that address this weakness (8)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
IA-1 | Policy and Procedures | IA | IA policy establishes password requirements, directly addressing weak password requirements. |
IA-5 | Authenticator Management | IA | Ensuring authenticators have sufficient strength of mechanism for intended use addresses weak password requirements. |
PM-15 | Security and Privacy Groups and Associations | PM | Facilitated training and awareness of current practices improves definition and enforcement of sufficiently strong password requirements. |
PM-3 | Information Security and Privacy Resources | PM | Dedicated security resources support deployment of strong authentication systems and enforcement of robust password policies. |
CM-6 | Configuration Settings | CM | Configuration settings can define and enforce strong password requirements to avoid weak policies. |
PL-9 | Central Management | PL | Organization-wide password and authentication policies are applied uniformly, preventing weak local password requirements. |
RA-5 | Vulnerability Monitoring and Scanning | RA | Vulnerability scans assess password policies and weak credential requirements against benchmarks. |
SA-5 | System Documentation | SA | User documentation on maintaining security includes password requirements, directly mitigating weak password policies. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2019-17444 UPD | 9.8 | 9.8 | 0.6945 | 2020-10-12 |
CVE-2017-3186 UPD | 8.0 | 9.8 | 0.0609 | 2017-12-16 |
CVE-2018-1000134 UPD | 7.9 | 9.8 | 0.0474 | 2018-03-16 |
CVE-2019-18988 KEV UPD | 7.9 | 7.0 | 0.0471 | 2020-02-07 |
CVE-2017-7903 UPD | 7.8 | 9.8 | 0.0276 | 2017-06-30 |
CVE-2017-12861 UPD | 7.8 | 9.8 | 0.0334 | 2017-10-10 |
CVE-2017-14189 UPD | 7.8 | 9.8 | 0.0278 | 2017-11-29 |
CVE-2020-11966 UPD | 7.8 | 9.8 | 0.0299 | 2020-04-21 |
CVE-2018-1372 UPD | 7.7 | 9.8 | 0.0215 | 2018-02-27 |
CVE-2017-1601 UPD | 7.7 | 9.8 | 0.0250 | 2018-05-02 |
CVE-2018-19064 UPD | 7.7 | 9.8 | 0.0199 | 2018-11-07 |
CVE-2019-9950 UPD | 7.7 | 9.8 | 0.0230 | 2019-04-24 |
CVE-2019-7488 UPD | 7.7 | 9.8 | 0.0189 | 2019-12-23 |
CVE-2020-26201 UPD | 7.7 | 9.8 | 0.0241 | 2020-12-10 |
CVE-2020-29591 UPD | 7.7 | 9.8 | 0.0261 | 2020-12-11 |
CVE-2022-1775 UPD | 7.7 | 9.8 | 0.0220 | 2022-05-20 |
CVE-2022-1668 UPD | 7.7 | 9.8 | 0.0214 | 2022-06-24 |
CVE-2017-1196 UPD | 7.6 | 9.8 | 0.0166 | 2017-06-07 |
CVE-2017-9853 UPD | 7.6 | 9.8 | 0.0172 | 2017-08-05 |
CVE-2017-1221 UPD | 7.6 | 9.8 | 0.0158 | 2017-11-13 |
CVE-2018-12925 UPD | 7.6 | 9.8 | 0.0146 | 2018-06-28 |
CVE-2019-7674 UPD | 7.6 | 9.8 | 0.0135 | 2019-02-09 |
CVE-2019-9123 UPD | 7.6 | 9.8 | 0.0150 | 2019-02-25 |
CVE-2019-13918 UPD | 7.6 | 9.8 | 0.0151 | 2019-09-13 |
CVE-2019-3758 UPD | 7.6 | 9.8 | 0.0146 | 2019-09-18 |