Cyber Posture

CWE · MITRE source

CWE-392Missing Report of Error Condition

Abstraction: Base · CVEs in our corpus: 11

The product encounters an error but does not provide a status code or return value to indicate that an error has occurred.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (6)AI

Control Title Family Why it addresses this CWE
IR-1Policy and ProceduresIRRequires reporting and escalation of error conditions and incidents per documented procedures.
IR-3Incident Response TestingIRIR testing would expose missing error reporting that prevents timely incident detection and response.
IR-7Incident Response AssistanceIROffers direct support for reporting incidents, addressing the failure to report error conditions or security events.
AU-5Response to Audit Logging Process FailuresAUMandates alerting on audit failures, directly providing the missing report of the error condition.
CA-7Continuous MonitoringCAReporting the security and privacy status to organizational officials ensures monitoring and assessment results are communicated rather than omitted.
PM-31Continuous Monitoring StrategyPMIncludes explicit reporting of security status and analysis results, addressing missing reports of error or monitoring conditions.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-424441.88.60.00552023-09-19
CVE-2023-424471.88.60.00522023-09-19
CVE-2025-327431.89.00.00452025-04-10
CVE-2024-396971.78.60.00152024-07-09
CVE-2017-23421.68.10.00112017-07-17
CVE-2025-232701.47.10.00032025-07-17
CVE-2024-127971.36.30.00722025-02-11
CVE-2026-200051.25.80.00032026-03-04
CVE-2025-262680.73.30.00242025-04-17
CVE-2025-593980.63.10.00022025-09-15
CVE-2023-484300.52.70.00102023-12-12