Cyber Posture

CWE · MITRE source

CWE-669Incorrect Resource Transfer Between Spheres

Abstraction: Class · CVEs in our corpus: 89

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (5)AI

Control Title Family Why it addresses this CWE
SC-32System PartitioningSCReduces incorrect transfers between spheres by establishing clear, separate domains for different sensitivities or functions.
SC-46Cross Domain Policy EnforcementSCIt governs all resource transfers between spheres, preventing incorrect or unauthorized movement of data or capabilities across domain interfaces.
AC-4Information Flow EnforcementACEnforces proper authorization rules for any resource or data transfer between different spheres.
MP-5Media TransportMPAccountability, documentation, and protection requirements ensure correct transfer of media resources between spheres.
SR-12Component DisposalSRAddresses incorrect transfer of resources to an uncontrolled sphere by requiring approved destruction or sanitization methods.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-10485.97.80.72782020-05-21
CVE-2026-31431 KEV3.87.80.03912026-04-22
CVE-2021-22900 KEV3.57.20.00732021-05-27
CVE-2002-00552.90.00.48422002-03-08
CVE-2019-130252.69.80.10812019-10-02
CVE-2016-50622.09.80.00482016-09-29
CVE-2020-158922.09.80.00922020-07-22
CVE-2020-58002.09.80.00442020-12-07
CVE-2020-246832.09.80.00452020-12-22
CVE-2021-301202.09.90.00412021-07-09
CVE-2022-44462.09.80.00722022-12-13
CVE-2025-678952.09.80.00442025-12-17
CVE-2020-68621.95.30.13272020-01-17
CVE-2022-206581.99.60.00262022-01-14
CVE-2019-118751.88.80.00342019-05-24
CVE-2019-132631.88.80.00122019-08-27
CVE-2019-132661.88.80.00112019-08-27
CVE-2020-259171.88.80.00292020-12-26
CVE-2021-246021.88.80.00662021-08-23
CVE-2021-458911.88.80.00422022-04-05
CVE-2023-311141.89.10.00332023-06-07
CVE-2026-252531.88.80.00092026-02-01
CVE-2025-416601.88.80.00272026-03-24
CVE-2020-152571.75.20.11152020-12-01
CVE-2022-302361.78.20.00432022-06-02