Cyber Posture

CWE · MITRE source

CWE-391Unchecked Error Condition

Abstraction: Base · CVEs in our corpus: 23

[PLANNED FOR DEPRECATION. SEE MAINTENANCE NOTES AND CONSIDER CWE-252, CWE-248, OR CWE-1069.] Ignoring exceptions and other error conditions may allow an attacker to induce unexpected behavior unnoticed.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (5)AI

Control Title Family Why it addresses this CWE
IR-1Policy and ProceduresIRPolicy enforces checking and handling of error conditions as part of incident response processes.
IR-3Incident Response TestingIRTesting IR effectiveness identifies and drives fixes for unchecked error conditions that fail to initiate incident handling.
IR-4Incident HandlingIRFormal incident handling procedures enforce checking and acting on error conditions that could indicate security incidents.
AU-5Response to Audit Logging Process FailuresAUEnsures audit logging process failures are checked and trigger defined responses instead of remaining unchecked.
PM-31Continuous Monitoring StrategyPMMandates ongoing correlation, analysis, and response to monitoring results, reducing unchecked error conditions from control assessments.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-523162.19.80.02672024-11-18
CVE-2017-121762.09.80.00952018-01-24
CVE-2017-121772.09.80.00952018-01-24
CVE-2017-121782.09.80.00872018-01-24
CVE-2017-121792.09.80.00842018-01-24
CVE-2017-121802.09.80.00872018-01-24
CVE-2017-121812.09.80.00842018-01-24
CVE-2017-121822.09.80.00952018-01-24
CVE-2017-121832.09.80.00872018-01-24
CVE-2017-121842.09.80.00842018-01-24
CVE-2017-121852.09.80.00842018-01-24
CVE-2017-121862.09.80.00752018-01-24
CVE-2017-121872.09.80.00772018-01-24
CVE-2016-105261.78.60.00302018-05-31
CVE-2019-148531.57.50.00072019-11-26
CVE-2017-74961.47.00.00052017-06-26
CVE-2020-143831.36.50.00462020-12-02
CVE-2022-221601.36.50.00082022-01-19
CVE-2024-233261.25.90.00082024-06-04
CVE-2022-208491.26.10.00052024-11-15
CVE-2018-10911.15.50.00082018-03-27
CVE-2023-05721.15.30.00242023-01-29
CVE-2023-328711.15.30.00002024-05-06