Cyber Resilience

CWE · MITRE source

CWE-665Improper Initialization

Abstraction: Class · CVEs in our corpus: 356

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-4 Information in Shared System Resources
  • SI-14 Non-persistence
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (2)AI-assisted

Control Title Family Why it addresses this CWE
SC-4Information in Shared System ResourcesSCEnsures shared resources are explicitly initialized or cleared on allocation, preventing exposure of prior contents to new users or processes.
SI-14Non-persistenceSIMandates that every instance begins in a known (presumably clean) state, eliminating reliance on residual or uninitialized state left by prior executions.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-46164 9.19.40.48992022-12-05
CVE-2022-37128 8.69.80.21252022-08-31
CVE-2019-14271 8.59.80.18832019-07-29
CVE-2022-0847 KEV 8.57.80.88612022-03-10
CVE-2022-22719 8.47.50.69802022-03-14
CVE-2008-0062 8.29.80.10142008-03-19
CVE-2017-13715 8.29.80.09652017-08-29
CVE-2020-28019 8.27.50.61662021-05-06
CVE-2015-8367 8.09.80.05452020-01-14
CVE-2019-3464 7.99.80.04702019-02-06
CVE-2013-1675 KEV 7.76.50.06702013-05-16
CVE-2019-10196 7.69.80.01392021-03-19
CVE-2021-41264 7.69.80.01442021-11-12
CVE-2024-39864 7.69.80.01772024-07-05
CVE-2018-11949 7.59.80.00952019-05-24
CVE-2020-27950 KEV 7.55.50.16352020-12-08
CVE-2024-38558 7.510.00.00822024-06-19
CVE-2001-1471 7.38.80.07702001-07-31
CVE-2017-5468 7.39.10.02442018-06-11
CVE-2021-33635 7.39.80.00562023-10-29
CVE-2024-46697 7.39.80.00422024-09-13
CVE-2008-3637 7.28.80.05732008-09-26
CVE-2026-647757.29.80.00372026-07-27
CVE-2018-10484 7.08.80.02742018-05-17
CVE-2018-14282 7.08.80.02772018-07-31