An attribute or characteristic that may, under known or unknown conditions, render an entity, asset, system, network, or geographic area open to exploitation or susceptible to a given hazard.
Sources:
CNSSI 4009-2022
from
DHS Lexicon Terms and Definitions
Defect or characteristic that may lead to undesirable behavior.
Sources:
NIST SP 800-160v1r1
from
ISO/SAE 21434:2021
(As used in this volume) Poor coding practices, as exemplified by CWEs
Sources:
NISTIR 8011 Vol. 4
A condition in a software, firmware, hardware, or service component that, under certain circumstances, could contribute to the introduction of vulnerabilities.
Sources:
NIST IR 8517
from
MITRE CWE
A bug or fault type that can be exploited through an operation that results in a security-relevant error.
Sources:
NIST IR 8517
from
Bellay21