Cyber Posture

CWE · MITRE source

CWE-684Incorrect Provision of Specified Functionality

Abstraction: Class · CVEs in our corpus: 27

The code does not function according to its published specifications, potentially leading to incorrect usage.

When providing functionality to an external party, it is important that the product behaves in accordance with the details specified. When requirements of nuances are not documented, the functionality may produce unintended behaviors for the caller, possibly leading to an exploitable state.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SI-6Security and Privacy Function VerificationSIPeriodic checks confirm that specified security and privacy functions are actually provided and operating.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-503572.09.80.00192024-11-29
CVE-2024-64251.99.10.00502024-07-01
CVE-2023-248451.89.10.00242023-08-08
CVE-2023-53631.87.50.04872023-10-25
CVE-2023-42581.78.60.00172023-09-25
CVE-2025-472271.77.50.03432025-07-05
CVE-2025-583251.68.20.00022025-10-14
CVE-2025-663841.68.20.00082025-11-28
CVE-2024-203171.57.40.00222024-09-11
CVE-2026-307911.57.50.00022026-03-05
CVE-2026-35981.57.50.00022026-03-05
CVE-2026-344781.57.50.00152026-04-10
CVE-2026-422551.47.20.00042026-04-26
CVE-2023-51581.36.50.00012023-09-25
CVE-2026-406851.36.50.00072026-04-30
CVE-2022-237281.26.10.00022022-01-21
CVE-2026-406841.25.90.00072026-04-30
CVE-2024-65021.15.70.00072024-08-22
CVE-2024-50050.94.30.00092024-10-11
CVE-2025-545670.84.20.00012025-07-25
CVE-2020-110540.73.50.00652020-05-07
CVE-2025-545680.73.70.00062025-07-25
CVE-2026-353790.73.30.00012026-04-22
CVE-2026-353810.73.30.00012026-04-22
CVE-2026-445970.73.70.00022026-05-07