Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SI

SI-2Flaw Remediation

Identify, report, and correct system flaws; Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; Install security-relevant software and firmware updates within {{ insert: param, si-02_odp }} of the release of the updates; and Incorporate flaw remediation into the organizational configuration management process.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (1)

ATT&CK techniques this control mitigates (84)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-327Use of a Broken or Risky Cryptographic Algorithm736Flaw remediation replaces broken or risky cryptographic algorithms once safer implementations are released by vendors.
CWE-326Inadequate Encryption Strength513Prompt patching corrects inadequate encryption strength when vendors release updates that increase key sizes or algorithm security.
CWE-328Use of Weak Hash58Security updates supplant weak hashing algorithms with stronger alternatives before attackers can exploit the original weakness.
CWE-1104Use of Unmaintained Third Party Components19Timely identification and installation of updates directly prevents use of unmaintained third-party components whose known flaws remain exploitable.
CWE-477Use of Obsolete Function16Software and firmware updates replace obsolete functions whose retained presence leaves systems exposed to publicly known weaknesses.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-50603 KEV9.710.00.9436good
CVE-2024-13160 KEV9.69.80.9381good
CVE-2025-24016 KEV9.69.90.9351good
CVE-2025-24893 KEV9.69.80.9366good
CVE-2024-13159 KEV9.69.80.9396good
CVE-2024-55591 KEV9.69.80.9406good
CVE-2024-53704 KEV9.69.80.9386good
CVE-2025-24813 KEV9.69.80.9414good
CVE-2025-47812 KEV9.610.00.9284good
CVE-2026-24061 KEV9.59.80.9230good
CVE-2025-64446 KEV9.59.80.9291good
CVE-2025-0282 KEV9.49.00.9413good
CVE-2024-48248 KEV9.48.60.9401good
CVE-2024-13161 KEV9.49.80.9132good
CVE-2025-2747 KEV9.49.80.9126good
CVE-2025-61882 KEV9.39.80.8938good
CVE-2025-2746 KEV9.39.80.8973good
CVE-2025-53770 KEV9.39.80.8854good
CVE-2025-40551 KEV9.29.80.8667good
CVE-2025-61757 KEV9.29.80.8783good
CVE-2025-52691 KEV9.210.00.8640good
CVE-2024-57727 KEV9.17.50.9402good
CVE-2025-37164 KEV9.110.00.8521good
CVE-2026-1731 KEV8.99.80.8150good
CVE-2026-1281 KEV8.99.80.8213good

Other controls in family SI

SI-1 SI-10 SI-11 SI-12 SI-13 SI-14 SI-15 SI-16 SI-17 SI-18 SI-19 SI-20 SI-21 SI-22 SI-23 SI-3 SI-4 SI-5 SI-6 SI-7 SI-8 SI-9