NIST 800-53 r5 · Controls catalogue · Family SA
SA-22Unsupported System Components
Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or Provide the following options for alternative sources for continued support for unsupported components {{ insert: param, sa-22_odp.01 }}.
Last updated: 20 August 2026 14:15 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): OWASP-Web 1 (partial)
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (6)
- T1189 Drive-by Compromise Initial Access
- T1195 Supply Chain Compromise Initial Access
- T1195.001 Compromise Software Dependencies and Development Tools Initial Access
- T1195.002 Compromise Software Supply Chain Initial Access
- T1543 Create or Modify System Process Persistence, Privilege Escalation
- T1543.002 Systemd Service Persistence, Privilege Escalation
Weaknesses this control addresses (2)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-1104 | Use of Unmaintained Third Party Components | 26 | Directly prevents continued use of components that receive no further security updates or patches from the vendor. |
CWE-477 | Use of Obsolete Function | 16 | Eliminates reliance on functions or components explicitly declared obsolete and unsupported by their maintainers. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-34192 UPD | 7.5 | 9.8 | 0.0096 | good |
CVE-2025-40906 UPD | 7.4 | 9.8 | 0.0061 | good |
CVE-2025-10220 UPD | 7.4 | 9.8 | 0.0073 | good |
CVE-2025-34193 UPD | 7.4 | 9.8 | 0.0078 | good |
CVE-2026-16634 | 7.4 | 9.8 | 0.0077 | good |
CVE-2025-12104 UPD | 7.3 | 9.8 | 0.0038 | good |
CVE-2026-3031 | 7.3 | 9.8 | 0.0040 | good |
CVE-2022-34381 UPD | 7.0 | 9.1 | 0.0098 | good |
CVE-2024-11999 UPD | 6.6 | 8.8 | 0.0064 | good |
CVE-2026-60368 | 6.5 | 8.8 | 0.0031 | good |
CVE-2024-35252 UPD | 6.3 | 7.5 | 0.0246 | good |
CVE-2025-3497 UPD | 6.2 | 8.7 | 0.0033 | good |
CVE-2026-41468 | 6.2 | 8.7 | 0.0039 | good |
CVE-2024-8885 UPD | 5.9 | 8.8 | 0.0011 | good |
CVE-2026-48573 UPD | 5.9 | 7.9 | 0.0103 | good |
CVE-2026-48576 UPD | 5.9 | 7.9 | 0.0103 | good |
CVE-2025-20010 UPD | 5.7 | 7.8 | 0.0024 | good |
CVE-2026-21821 UPD | 5.7 | 8.3 | 0.0021 | good |
CVE-2026-41097 UPD | 5.4 | 6.7 | 0.0142 | good |
CVE-2024-21631 UPD | 5.2 | 6.5 | 0.0060 | good |
CVE-2026-21265 UPD | 5.1 | 6.4 | 0.0100 | good |
CVE-2023-37524 UPD | 5.1 | 7.7 | 0.0010 | good |
CVE-2025-48862 UPD | 4.9 | 7.1 | 0.0011 | good |
CVE-2025-52658 | 2.9 | 3.5 | 0.0018 | good |
CVE-2025-55277 | 2.4 | 2.6 | 0.0018 | good |