NIST 800-53 r5 · Controls catalogue · Family SA
SA-19Component Authenticity
Component Authenticity
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (7)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-295 | Improper Certificate Validation | 1,700+ | When certificates are used to establish component provenance, the control requires correct certificate validation procedures. |
CWE-347 | Improper Verification of Cryptographic Signature | 900+ | Component authenticity commonly depends on cryptographic signatures; the control enforces proper verification of those signatures. |
CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | 300+ | Mandates acquisition only from trusted suppliers and verified authentic sources, reducing inclusion of functionality from untrusted control spheres. |
CWE-494 | Download of Code Without Integrity Check | 200+ | Component authenticity requires verifying origin/integrity of acquired firmware or software, directly preventing inclusion of code without integrity checks. |
CWE-506 | Embedded Malicious Code | 99 | Authenticity verification and anti-counterfeit procedures detect and block components that may contain embedded malicious code or backdoors. |
CWE-353 | Missing Support for Integrity Check | 44 | Explicitly requires support for integrity and authenticity checks on components before acceptance into the system. |
CWE-1104 | Use of Unmaintained Third Party Components | 26 | Requires use of trusted, maintained suppliers and configuration control, making use of unmaintained third-party components far less likely. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-32800 UPD | 7.4 | 9.8 | 0.0057 | good |
CVE-2024-3313 UPD | 6.2 | 8.4 | 0.0026 | good |
CVE-2024-28042 UPD | 6.1 | 8.4 | 0.0021 | good |
CVE-2024-26024 UPD | 6.1 | 8.4 | 0.0021 | good |
CVE-2026-47619 | 5.1 | 6.6 | 0.0045 | good |
CVE-2024-3094 UPD | 10.0 | 10.0 | 0.8597 | partial |
CVE-2025-59374 KEV | 9.9 | 9.8 | 0.0117 | partial |
CVE-2026-8398 KEV UPD | 9.9 | 9.8 | 0.0146 | partial |
CVE-2026-48027 KEV UPD | 9.9 | 9.8 | 0.0185 | partial |
CVE-2026-45321 KEV UPD | 9.4 | 9.6 | 0.0234 | partial |
CVE-2026-33634 KEV | 9.2 | 8.8 | 0.5916 | partial |
CVE-2025-30066 KEV UPD | 8.8 | 8.6 | 0.6979 | partial |
CVE-2025-30154 KEV UPD | 8.8 | 8.6 | 0.0239 | partial |
CVE-2024-4978 KEV UPD | 8.6 | 8.4 | 0.2694 | partial |
CVE-2025-54313 KEV UPD | 8.1 | 7.5 | 0.0415 | partial |
CVE-2026-46412 | 7.4 | 10.0 | 0.0042 | partial |
CVE-2026-18072 | 7.4 | 9.8 | 0.0059 | partial |
CVE-2026-66747 | 7.4 | 9.8 | 0.0058 | partial |
CVE-2026-31976 | 7.3 | 9.8 | 0.0050 | partial |
CVE-2026-34424 | 7.3 | 9.8 | 0.0055 | partial |
CVE-2026-6443 | 7.3 | 9.8 | 0.0050 | partial |
CVE-2026-73532 | 7.3 | 9.8 | 0.0046 | partial |
CVE-2026-73533 | 7.3 | 9.8 | 0.0045 | partial |
CVE-2026-77649 | 7.3 | 9.8 | 0.0043 | partial |
CVE-2026-77650 | 7.3 | 9.8 | 0.0043 | partial |