NIST 800-53 r5 · Controls catalogue · Family SC
SC-11Trusted Path
Provide a {{ insert: param, sc-11_odp.01 }} isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users to invoke the trusted communications path for communications between the user and the following security functions of the system, including at a minimum, authentication and re-authentication: {{ insert: param, sc-11_odp.02 }}.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (6)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-346 | Origin Validation Error | 700+ | Trusted path establishment enforces validation that the communication originates from and reaches only the intended trusted system components. |
CWE-290 | Authentication Bypass by Spoofing | 700+ | Isolated trusted path ensures the user interacts only with genuine system components, preventing spoofing of authentication interfaces or prompts. |
CWE-288 | Authentication Bypass Using an Alternate Path or Channel | 600+ | Requires authentication to occur exclusively over the isolated trusted path, directly preventing bypass via alternate or untrusted channels. |
CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | 69 | Mandates restriction of the channel for authentication to only the intended trusted endpoints, blocking unauthorized communication paths. |
CWE-940 | Improper Verification of Source of a Communication Channel | 56 | Requires explicit verification of the source and integrity of the channel used for authentication and other security functions. |
CWE-300 | Channel Accessible by Non-Endpoint | 55 | Explicitly isolates the communications path so it cannot be accessed or intercepted by non-endpoint entities during security functions. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2023-31004 UPD | 6.1 | 8.3 | 0.0099 | good |
CVE-2025-31214 UPD | 6.1 | 8.1 | 0.0052 | good |
CVE-2024-36553 UPD | 6.0 | 8.1 | 0.0030 | good |
CVE-2024-32049 UPD | 5.7 | 7.4 | 0.0055 | good |
CVE-2025-20122 UPD | 5.6 | 7.8 | 0.0015 | good |
CVE-2026-12991 | 5.5 | 8.7 | 0.0014 | good |
CVE-2025-40770 UPD | 5.3 | 7.4 | 0.0012 | good |
CVE-2025-54792 UPD | 5.1 | 6.8 | 0.0026 | good |
CVE-2024-45407 UPD | 5.0 | 6.5 | 0.0034 | good |
CVE-2024-12602 UPD | 4.7 | 6.2 | 0.0024 | good |
CVE-2023-38272 UPD | 4.6 | 5.9 | 0.0033 | good |
CVE-2024-50568 UPD | 4.6 | 5.9 | 0.0037 | good |
CVE-2019-19751 UPD | 4.4 | 5.6 | 0.0029 | good |
CVE-2024-27263 UPD | 4.1 | 5.3 | 0.0027 | good |
CVE-2026-23810 | 3.5 | 4.3 | 0.0018 | good |
CVE-2026-23811 | 3.5 | 4.3 | 0.0015 | good |
CVE-2026-23812 | 3.5 | 4.3 | 0.0015 | good |
CVE-2024-50565 UPD | 2.8 | 3.1 | 0.0038 | good |
CVE-2024-31206 UPD | 6.2 | 8.2 | 0.0033 | good |