Cyber Posture

CWE · MITRE source

CWE-521Weak Password Requirements

Abstraction: Base · CVEs in our corpus: 254

The product does not require that users should have strong passwords.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (8)AI

Control Title Family Why it addresses this CWE
IA-1Policy and ProceduresIAIA policy establishes password requirements, directly addressing weak password requirements.
IA-5Authenticator ManagementIAEnsuring authenticators have sufficient strength of mechanism for intended use addresses weak password requirements.
PM-15Security and Privacy Groups and AssociationsPMFacilitated training and awareness of current practices improves definition and enforcement of sufficiently strong password requirements.
PM-3Information Security and Privacy ResourcesPMDedicated security resources support deployment of strong authentication systems and enforcement of robust password policies.
CM-6Configuration SettingsCMConfiguration settings can define and enforce strong password requirements to avoid weak policies.
PL-9Central ManagementPLOrganization-wide password and authentication policies are applied uniformly, preventing weak local password requirements.
RA-5Vulnerability Monitoring and ScanningRAVulnerability scans assess password policies and weak credential requirements against benchmarks.
SA-5System DocumentationSAUser documentation on maintaining security includes password requirements, directly mitigating weak password policies.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-174447.59.80.92492020-10-12
CVE-2024-428504.99.80.49782024-08-16
CVE-2019-18988 KEV3.97.00.07632020-02-07
CVE-2017-31862.69.80.09872017-12-16
CVE-2023-377562.49.80.06642023-09-14
CVE-2017-128612.29.80.03722017-10-10
CVE-2024-488452.29.40.05472024-12-05
CVE-2018-10001342.19.80.01682018-03-16
CVE-2020-295912.19.80.02662020-12-11
CVE-2022-454822.19.80.01862022-12-02
CVE-2017-11962.09.80.00312017-06-07
CVE-2017-79032.09.80.00232017-06-30
CVE-2017-98532.09.80.00332017-08-05
CVE-2017-12212.09.80.00262017-11-13
CVE-2017-141892.09.80.00542017-11-29
CVE-2018-13722.09.80.00312018-02-27
CVE-2017-16012.09.80.00502018-05-02
CVE-2018-129252.09.80.00282018-06-28
CVE-2018-190642.09.80.00802018-11-07
CVE-2018-157192.09.80.00162018-12-12
CVE-2019-76742.09.80.00412019-02-09
CVE-2019-91232.09.80.00562019-02-25
CVE-2019-99502.09.80.00192019-04-24
CVE-2019-139182.09.80.00482019-09-13
CVE-2019-37582.09.80.00472019-09-18