Cyber Resilience

CWE · MITRE source

CWE-669Incorrect Resource Transfer Between Spheres

Abstraction: Class · CVEs in our corpus: 104

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-32 System Partitioning
  • SC-46 Cross Domain Policy Enforcement
  • AC-4 Information Flow Enforcement
  • MP-5 Media Transport
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 2 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (5)AI-assisted

Control Title Family Why it addresses this CWE
SC-32System PartitioningSCReduces incorrect transfers between spheres by establishing clear, separate domains for different sensitivities or functions.
SC-46Cross Domain Policy EnforcementSCIt governs all resource transfers between spheres, preventing incorrect or unauthorized movement of data or capabilities across domain interfaces.
AC-4Information Flow EnforcementACEnforces proper authorization rules for any resource or data transfer between different spheres.
MP-5Media TransportMPAccountability, documentation, and protection requirements ensure correct transfer of media resources between spheres.
SR-12Component DisposalSRAddresses incorrect transfer of resources to an uncontrolled sphere by requiring approved destruction or sanitization methods.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-31431 KEV 8.57.80.99912026-04-22
CVE-2021-22900 KEV 8.17.20.14152021-05-27
CVE-2016-5062 7.99.80.03932016-09-29
CVE-2019-13025 7.89.80.03322019-10-02
CVE-2020-15892 7.69.80.01642020-07-22
CVE-2020-5800 7.69.80.01562020-12-07
CVE-2020-24683 7.69.80.01462020-12-22
CVE-2021-30120 7.69.90.05702021-07-09
CVE-2022-4446 7.59.80.01272022-12-13
CVE-2025-678957.59.80.00982025-12-17
CVE-2026-25253 7.48.80.08022026-02-01
CVE-2022-20658 7.19.60.01392022-01-14
CVE-2019-11875 7.08.80.02272019-05-24
CVE-2020-1048 7.07.80.16502020-05-21
CVE-2023-31114 6.99.10.00562023-06-07
CVE-2019-13263 6.88.80.01172019-08-27
CVE-2020-25917 6.88.80.01242020-12-26
CVE-2021-24602 6.88.80.01512021-08-23
CVE-2021-45891 6.88.80.01402022-04-05
CVE-2019-13266 6.78.80.00972019-08-27
CVE-2025-416606.58.80.00432026-03-24
CVE-2019-11770 6.48.10.01272019-06-14
CVE-2022-30236 6.48.20.00772022-06-02
CVE-2018-17791 6.27.50.01912019-08-21
CVE-2012-2979 6.27.50.01742019-11-01