Cyber Resilience

CWE · MITRE source

CWE-232Improper Handling of Undefined Values

Abstraction: Variant · CVEs in our corpus: 11

The product does not handle or incorrectly handles when a value is not defined or supported for the associated parameter, field, or argument name.

Last updated: 22 August 2026 14:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SI-10 Information Input Validation
  • SI-11 Error Handling
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-40775 6.97.50.15222025-05-21
CVE-2023-2968 6.17.50.01482023-05-30
CVE-2023-39914 5.97.50.00592023-09-13
CVE-2023-39915 5.97.50.00522023-09-13
CVE-2025-20192 5.67.70.00432025-05-07
CVE-2023-36848 5.06.50.00302023-07-14
CVE-2026-216895.06.50.00282026-01-07
CVE-2025-20314 4.96.70.00152025-09-24
CVE-2022-22213 4.85.90.00682022-07-20
CVE-2021-34705 4.75.30.01012021-09-23
CVE-2021-3718 3.54.30.00212021-11-12