NIST 800-53 r5 · Controls catalogue · Family SC
SC-24Fail in Known State
Fail to a {{ insert: param, sc-24_odp.02 }} for the following failures on the indicated components while preserving {{ insert: param, sc-24_odp.03 }} in failure: {{ insert: param, sc-24_odp.01 }}.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (6)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-754 | Improper Check for Unusual or Exceptional Conditions | 700+ | Requires detection of unusual conditions followed by a controlled transition to the defined failure state. |
CWE-755 | Improper Handling of Exceptional Conditions | 600+ | Enforces structured response to exceptional conditions so the system cannot remain in an unsafe state. |
CWE-248 | Uncaught Exception | 200+ | Prevents abrupt termination from uncaught exceptions by requiring a defined, preserved-state failure mode. |
CWE-703 | Improper Check or Handling of Exceptional Conditions | 100+ | Mandates explicit, predictable handling of exceptional conditions rather than undefined continuation. |
CWE-636 | Not Failing Securely ('Failing Open') | 46 | Directly requires transition to a known (secure) state on failure, preventing fail-open behavior. |
CWE-390 | Detection of Error Condition Without Action | 20 | Ensures that detected error conditions trigger an explicit action to reach the known failure state. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-29748 KEV UPD | 8.5 | 7.8 | 0.0068 | good |
CVE-2025-10156 UPD | 7.6 | 9.8 | 0.0148 | good |
CVE-2024-21907 UPD | 7.5 | 7.5 | 0.3291 | good |
CVE-2021-42141 UPD | 7.5 | 9.8 | 0.0118 | good |
CVE-2024-43532 UPD | 7.5 | 8.8 | 0.1197 | good |
CVE-2024-26584 UPD | 7.4 | 9.8 | 0.0075 | good |
CVE-2024-3729 UPD | 7.4 | 9.8 | 0.0081 | good |
CVE-2026-22034 UPD | 7.4 | 9.8 | 0.0067 | good |
CVE-2022-48673 UPD | 7.3 | 9.8 | 0.0050 | good |
CVE-2025-13021 UPD | 7.2 | 9.8 | 0.0036 | good |
CVE-2025-13022 UPD | 7.2 | 9.8 | 0.0036 | good |
CVE-2025-13023 UPD | 7.2 | 9.8 | 0.0036 | good |
CVE-2025-13026 UPD | 7.2 | 9.8 | 0.0036 | good |
CVE-2025-43864 UPD | 7.1 | 7.5 | 0.2021 | good |
CVE-2023-45927 UPD | 7.0 | 9.1 | 0.0084 | good |
CVE-2024-22590 UPD | 6.9 | 9.1 | 0.0058 | good |
CVE-2026-40525 UPD | 6.9 | 9.1 | 0.0057 | good |
CVE-2023-6267 UPD | 6.7 | 8.6 | 0.0072 | good |
CVE-2024-3150 UPD | 6.7 | 8.8 | 0.0079 | good |
CVE-2024-10781 UPD | 6.7 | 8.1 | 0.0379 | good |
CVE-2025-59538 | 6.7 | 7.5 | 0.0834 | good |
CVE-2026-27586 | 6.7 | 9.1 | 0.0027 | good |
CVE-2024-7521 | 6.6 | 8.8 | 0.0062 | good |
CVE-2026-40371 UPD | 6.6 | 8.8 | 0.0063 | good |
CVE-2026-68746 | 6.6 | 8.8 | 0.0045 | good |