Cyber Posture

CWE · MITRE source

CWE-610Externally Controlled Reference to a Resource in Another Sphere

Abstraction: Class · CVEs in our corpus: 221

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SI-22Information DiversitySILimits impact of an externally controlled reference to a primary information resource by switching to an identified alternative.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-27593 KEV9.610.00.93122022-09-08
CVE-2020-54126.86.50.92362020-08-07
CVE-2022-26336.87.50.88352022-09-06
CVE-2017-183574.76.50.57292019-01-15
CVE-2025-0111 KEV3.56.50.03692025-02-12
CVE-2023-309432.96.50.26762023-05-02
CVE-2022-24312.68.10.17142022-09-06
CVE-2017-02112.45.50.22342017-04-12
CVE-2021-276482.49.00.09892021-04-28
CVE-2024-109792.28.80.06862024-11-14
CVE-2017-160882.110.00.02062018-06-07
CVE-2020-140572.19.80.03072020-07-01
CVE-2024-477732.18.20.07852024-10-08
CVE-2019-72902.010.00.00522019-12-18
CVE-2020-97522.09.80.00502020-03-23
CVE-2021-436852.09.80.00432021-12-01
CVE-2021-440412.09.80.00832021-12-14
CVE-2022-202392.09.80.00082022-08-10
CVE-2022-392062.09.90.01052022-09-13
CVE-2024-247602.08.80.04052024-02-02
CVE-2025-221442.09.80.00352025-01-13
CVE-2021-438441.98.80.02502021-12-20
CVE-2020-251611.88.80.00632021-02-23
CVE-2021-302451.88.80.00402021-04-15
CVE-2021-412441.89.10.00492021-11-15