Cyber Resilience

CWE · MITRE source

CWE-703Improper Check or Handling of Exceptional Conditions

Abstraction: Pillar · CVEs in our corpus: 162

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Last updated: 20 August 2026 13:14 UTC

OWASP Top 10 for Web (2025)

This weakness contributes to A10:2025 Mishandling of Exceptional Conditions.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • CP-12 Safe Mode
  • CP-3 Contingency Training
  • CP-4 Contingency Plan Testing
  • CP-5 Contingency Plan Update
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (17)AI-assisted

Showing the 15 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
CP-12Safe ModeCPProvides a defined response to detected conditions by restricting operation, ensuring exceptional conditions are handled rather than ignored or mishandled.
CP-3Contingency TrainingCPContingency training equips users with defined procedures to check and respond to exceptional conditions during disruptions, reducing exploitation of mishandled errors.
CP-4Contingency Plan TestingCPTesting verifies the system's ability to detect, handle, and recover from exceptional conditions as part of the plan, reducing exploitability of improper exception handling.
IR-1Policy and ProceduresIRPolicy defines checks and handling for exceptional conditions arising from security incidents.
IR-3Incident Response TestingIRPerforming IR tests ensures exceptional conditions are properly checked and handled to enable effective response.
IR-4Incident HandlingIRIncident handling capability directly provides structured checking and response actions for security incidents as exceptional conditions.
SA-11Developer Testing and EvaluationSATesting and evaluation exercises error paths and exceptional conditions, surfacing improper handling that is then remediated through the defined process.
SA-15Development Process, Standards, and ToolsSAStandards and tools mandated by the process include proper handling of exceptional conditions that would otherwise be omitted.
SA-24Design For Cyber ResiliencySACyber resiliency objectives explicitly include graceful handling of adverse conditions and exceptional states, reducing improper exception handling.
SI-13Predictable Failure PreventionSIRequires systematic prediction and handling of failure conditions, reducing the impact of unhandled exceptional states.
SI-17Fail-safe ProceduresSIRequires explicit, safe handling actions for specified exceptional conditions rather than allowing unchecked propagation or default unsafe behavior.
SI-6Security and Privacy Function VerificationSIThe required verification process supplies the missing checks for exceptional conditions affecting security functions.
AU-5Response to Audit Logging Process FailuresAUImplements explicit check and handling for the exceptional condition of audit logging process failure.
CA-7Continuous MonitoringCAEstablishing and monitoring system metrics with correlation and response actions helps identify and address improper handling of exceptional conditions.
SC-24Fail in Known StateSCMandates explicit, predictable handling of exceptional conditions rather than undefined continuation.
Show 2 more broadly-applicable controls
CP-5Contingency Plan UpdateCPRegular updates keep contingency procedures aligned with system changes, providing structured handling for exceptional conditions that would otherwise allow unmitigated exploitation.
IR-7Incident Response AssistanceIRSupplies advice and assistance on handling incidents, improving checks and responses to exceptional conditions.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-21894 8.59.80.18992024-04-04
CVE-2021-25370 KEV 7.56.10.00892021-03-26
CVE-2021-25372 KEV 7.56.10.00802021-03-26
CVE-2022-22265 KEV 7.55.00.00392022-01-10
CVE-2019-5031 7.38.80.06012019-10-02
CVE-2025-13021 7.29.80.00362025-11-11
CVE-2025-13022 7.29.80.00362025-11-11
CVE-2025-13023 7.29.80.00362025-11-11
CVE-2025-13026 7.29.80.00362025-11-11
CVE-2021-23859 7.09.10.00972021-12-08
CVE-2023-45927 7.09.10.00842024-03-27
CVE-2023-0397 6.89.60.00472023-01-19
CVE-2021-3329 6.89.60.00622023-02-26
CVE-2024-22053 6.88.20.03532024-04-04
CVE-2024-10781 6.78.10.03792024-11-26
CVE-2025-595386.77.50.08342025-10-01
CVE-2023-49786 6.57.50.05342023-12-14
CVE-2024-39815 6.59.10.00772024-08-12
CVE-2018-12551 6.48.10.01472019-03-27
CVE-2024-22052 6.47.50.03752024-04-04
CVE-2024-21525 6.38.30.00542024-07-10
CVE-2017-16014 6.27.50.01692018-06-04
CVE-2022-25252 6.27.50.01572022-03-16
CVE-2024-29205 6.27.50.01582024-04-25
CVE-2020-1639 6.17.50.01092020-04-08