Cyber Resilience

CWE · MITRE source

CWE-341Predictable from Observable State

Abstraction: Base · CVEs in our corpus: 16

A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • IA-5 Authenticator Management
  • SC-12 Cryptographic Key Establishment and Management
  • SC-23 Session Authenticity
  • PR.PS-01
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V6.6.1
  • V6.5.1
  • V6.5.3
  • V6.5.5

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-6563 7.69.80.01752019-03-05
CVE-2026-389687.39.80.00382026-07-02
CVE-2020-1731 7.19.10.01282020-03-02
CVE-2026-5081 6.89.10.00302026-05-06
CVE-2025-40780 6.28.60.00462025-10-22
CVE-2026-42365 6.28.60.00342026-05-04
CVE-2023-49259 5.87.50.00312024-01-12
CVE-2026-40164 5.87.50.00372026-04-14
CVE-2026-36609 5.57.30.00172026-06-03
CVE-2026-155715.57.30.00312026-08-18
CVE-2018-17917 4.75.30.01252018-10-10
CVE-2020-5365 4.75.30.00992020-05-20
CVE-2025-48461 4.15.00.00432025-06-24
CVE-2025-42925 3.64.30.00232025-09-09
CVE-2024-101413.43.70.00812024-10-19
CVE-2021-4277 2.62.60.00452022-12-25