NIST 800-53 r5 · Controls catalogue · Family SI
SI-11Error Handling
Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to {{ insert: param, si-11_odp }}.
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): OWASP-Web 1 (partial)
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 11,000+ | Restricts error message visibility to authorized recipients, directly reducing unauthorized exposure of sensitive information. |
CWE-203 | Observable Discrepancy | 800+ | Prevents attackers from using observable differences in error responses to infer internal system details or state. |
CWE-209 | Generation of Error Message Containing Sensitive Information | 600+ | Explicitly requires error messages to avoid including sensitive or exploitable details while still supporting corrective action. |
CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | 300+ | Ensures sensitive system information is not disclosed outside the intended control sphere through error output. |
CWE-204 | Observable Response Discrepancy | 100+ | Eliminates distinguishable response discrepancies in error conditions that could be exploited for reconnaissance. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-62168 UPD | 9.6 | 10.0 | 0.6287 | good |
CVE-2024-29059 KEV UPD | 8.5 | 7.5 | 0.9862 | good |
CVE-2026-22778 UPD | 7.8 | 9.8 | 0.0372 | good |
CVE-2025-47813 KEV UPD | 7.5 | 4.3 | 0.5940 | good |
CVE-2024-6980 UPD | 7.3 | 9.8 | 0.0056 | good |
CVE-2025-46658 UPD | 7.2 | 9.8 | 0.0037 | good |
CVE-2024-28939 UPD | 7.0 | 8.8 | 0.0227 | good |
CVE-2024-23689 UPD | 6.6 | 8.8 | 0.0067 | good |
CVE-2024-38516 UPD | 6.6 | 8.8 | 0.0051 | good |
CVE-2024-54141 UPD | 6.6 | 8.6 | 0.0049 | good |
CVE-2024-39719 UPD | 6.4 | 7.5 | 0.0428 | good |
CVE-2026-53906 | 6.2 | 8.2 | 0.0034 | good |
CVE-2024-6984 UPD | 6.1 | 8.8 | 0.0038 | good |
CVE-2024-45784 UPD | 6.1 | 7.5 | 0.0134 | good |
CVE-2025-22218 UPD | 6.1 | 8.5 | 0.0066 | good |
CVE-2025-1395 UPD | 6.1 | 8.2 | 0.0030 | good |
CVE-2025-23320 UPD | 6.0 | 7.5 | 0.0091 | good |
CVE-2023-5392 UPD | 5.9 | 7.5 | 0.0048 | good |
CVE-2025-31001 UPD | 5.9 | 7.5 | 0.0048 | good |
CVE-2025-44203 UPD | 5.9 | 7.5 | 0.0050 | good |
CVE-2026-28811 | 5.9 | 7.5 | 0.0048 | good |
CVE-2024-45817 UPD | 5.8 | 7.3 | 0.0054 | good |
CVE-2024-11625 UPD | 5.8 | 7.7 | 0.0030 | good |
CVE-2025-40718 UPD | 5.8 | 7.5 | 0.0036 | good |
CVE-2025-36003 UPD | 5.8 | 7.5 | 0.0034 | good |