Cyber Resilience

CWE · MITRE source

CWE-436Interpretation Conflict

Abstraction: Class · CVEs in our corpus: 137

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

This is generally found in proxies, firewalls, anti-virus software, and other intermediary devices that monitor, allow, deny, or modify traffic based on how the client or server is expected to behave.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 3 mapping(s) from 1 framework(s): CAPEC 3 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A06:2025 Insecure Design.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SA-11 Developer Testing and Evaluation
  • SC-8 Transmission Confidentiality and Integrity
  • PR.PS-06
  • GV.SC-07
Detect
Catch it (CSF Detect / Respond)
  • DE.AE-03
  • DE.CM-09
Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-63030 KEV9.99.80.95602026-07-17
CVE-2025-25292 9.79.80.65092025-03-12
CVE-2021-28474 8.68.80.50632021-05-11
CVE-2025-25291 8.69.80.20262025-03-12
CVE-2025-48384 KEV 8.38.00.04112025-07-08
CVE-2023-24813 7.810.00.02492023-02-07
CVE-2021-45327 7.79.80.02142022-02-08
CVE-2019-19589 7.69.80.01772019-12-05
CVE-2020-10180 7.69.80.01692020-03-05
CVE-2019-18792 7.39.10.02522020-01-06
CVE-2026-8034 7.39.80.00382026-05-07
CVE-2026-477677.39.80.00392026-07-14
CVE-2022-37436 7.05.30.57942023-01-17
CVE-2023-39481 6.98.80.01582024-05-03
CVE-2024-38428 6.99.10.00672024-06-16
CVE-2026-33808 6.99.10.00482026-04-15
CVE-2026-6270 6.99.10.00502026-04-16
CVE-2026-33807 6.89.10.00432026-04-15
CVE-2026-412486.89.10.00322026-04-24
CVE-2026-141986.89.10.00302026-07-01
CVE-2019-17596 6.57.50.04692019-10-24
CVE-2021-1587 6.58.60.01682021-08-25
CVE-2026-736146.58.80.00362026-08-13
CVE-2026-736156.58.80.00362026-08-13
CVE-2022-36051 6.48.70.00802022-08-31