Cyber Resilience

CWE · MITRE source

CWE-755Improper Handling of Exceptional Conditions

Abstraction: Class · CVEs in our corpus: 585

The product does not handle or incorrectly handles an exceptional condition.

Last updated: 22 August 2026 14:14 UTC

OWASP Top 10 for Web (2025)

This weakness contributes to A10:2025 Mishandling of Exceptional Conditions.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • CP-12 Safe Mode
  • CP-3 Contingency Training
  • CP-5 Contingency Plan Update
  • IR-1 Policy and Procedures
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 1 hardening rule · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (10)AI-assisted

Control Title Family Why it addresses this CWE
CP-12Safe ModeCPSupplies a concrete handling action (safe mode) for exceptional conditions, mitigating risks from improper or absent handling that could allow continued attacks.
CP-3Contingency TrainingCPBy preparing users for contingency scenarios, the control promotes proper handling of exceptional conditions instead of default or unsafe behaviors.
CP-5Contingency Plan UpdateCPAn updated contingency plan defines current actions for exceptional conditions, reducing the window for attackers to exploit improper handling leading to system failure.
IR-1Policy and ProceduresIRProcedures ensure proper handling of exceptional conditions to support effective incident response.
IR-3Incident Response TestingIRIncident response testing confirms proper handling of exceptional conditions to limit exploit impact.
IR-7Incident Response AssistanceIRGives users guidance on incident handling, reducing improper handling of exceptional conditions that could stem from exploited weaknesses.
SI-13Predictable Failure PreventionSIPrepared component exchange provides a defined recovery path, making improper handling of failures less exploitable.
SI-17Fail-safe ProceduresSIMandates defined procedures that ensure exceptional conditions are handled in a controlled, secure manner instead of being ignored or mishandled.
AU-5Response to Audit Logging Process FailuresAUProvides defined handling (alert and additional actions) for the exceptional condition of audit logging failure.
SC-24Fail in Known StateSCEnforces structured response to exceptional conditions so the system cannot remain in an unsafe state.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-5638 KEV 9.99.81.00002017-03-11
CVE-2020-7247 KEV 9.99.80.98972020-01-29
CVE-2019-12815 9.59.80.57612019-07-19
CVE-2021-38003 KEV 9.28.80.38572021-11-23
CVE-2019-14287 8.98.80.63762019-10-17
CVE-2018-0155 KEV 8.88.60.07792018-03-28
CVE-2024-29748 KEV 8.57.80.00682024-04-05
CVE-2023-36933 8.47.50.72242023-07-05
CVE-2019-17195 8.29.80.11032019-10-15
CVE-2018-0934 8.17.50.66762018-03-14
CVE-2022-23121 8.19.80.08592023-03-28
CVE-2021-28165 8.07.50.53862021-04-01
CVE-2019-14431 7.89.80.03632019-07-29
CVE-2019-6848 7.88.60.32972019-10-29
CVE-2021-43272 7.89.80.03522021-11-14
CVE-2021-40391 7.89.80.02892021-11-19
CVE-2017-2877 7.79.80.01902018-09-19
CVE-2018-19991 7.79.80.02332018-12-10
CVE-2019-6256 7.79.80.02412019-01-14
CVE-2019-14378 7.78.80.16662019-07-29
CVE-2020-24753 7.79.80.02642020-09-17
CVE-2022-31799 7.79.80.02052022-06-02
CVE-2021-36128 7.69.80.01502021-07-02
CVE-2021-38384 7.69.80.01462021-08-10
CVE-2022-48328 7.69.80.01302023-02-20