Cyber Resilience

CWE · MITRE source

CWE-392Missing Report of Error Condition

Abstraction: Base · CVEs in our corpus: 12

The product encounters an error but does not provide a status code or return value to indicate that an error has occurred.

Last updated: 21 August 2026 14:15 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • IR-1 Policy and Procedures
  • IR-3 Incident Response Testing
  • IR-7 Incident Response Assistance
  • AU-5 Response to Audit Logging Process Failures
Detect
Catch it (CSF Detect / Respond)
  • DE.CM-09
Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (6)AI-assisted

Control Title Family Why it addresses this CWE
IR-1Policy and ProceduresIRRequires reporting and escalation of error conditions and incidents per documented procedures.
IR-3Incident Response TestingIRIR testing would expose missing error reporting that prevents timely incident detection and response.
IR-7Incident Response AssistanceIROffers direct support for reporting incidents, addressing the failure to report error conditions or security events.
AU-5Response to Audit Logging Process FailuresAUMandates alerting on audit failures, directly providing the missing report of the error condition.
CA-7Continuous MonitoringCAReporting the security and privacy status to organizational officials ensures monitoring and assessment results are communicated rather than omitted.
PM-31Continuous Monitoring StrategyPMIncludes explicit reporting of security status and analysis results, addressing missing reports of error or monitoring conditions.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-42444 6.38.60.00692023-09-19
CVE-2023-42447 6.38.60.00522023-09-19
CVE-2024-39697 6.38.60.00712024-07-09
CVE-2025-32743 6.39.00.00482025-04-10
CVE-2017-2342 6.28.10.00572017-07-17
CVE-2026-42246 5.67.40.00312026-05-09
CVE-2024-12797 5.46.30.02482025-02-11
CVE-2025-23270 4.97.10.00192025-07-17
CVE-2026-200054.65.80.00492026-03-04
CVE-2025-26268 3.03.30.00392025-04-17
CVE-2023-48430 2.72.70.00592023-12-12
CVE-2025-59398 2.73.10.00242025-09-15