CWE · MITRE source
CWE-755Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
Last updated: 22 August 2026 14:14 UTC
OWASP Top 10 for Web (2025)
This weakness contributes to A10:2025 Mishandling of Exceptional Conditions.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (10)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
CP-12 | Safe Mode | CP | Supplies a concrete handling action (safe mode) for exceptional conditions, mitigating risks from improper or absent handling that could allow continued attacks. |
CP-3 | Contingency Training | CP | By preparing users for contingency scenarios, the control promotes proper handling of exceptional conditions instead of default or unsafe behaviors. |
CP-5 | Contingency Plan Update | CP | An updated contingency plan defines current actions for exceptional conditions, reducing the window for attackers to exploit improper handling leading to system failure. |
IR-1 | Policy and Procedures | IR | Procedures ensure proper handling of exceptional conditions to support effective incident response. |
IR-3 | Incident Response Testing | IR | Incident response testing confirms proper handling of exceptional conditions to limit exploit impact. |
IR-7 | Incident Response Assistance | IR | Gives users guidance on incident handling, reducing improper handling of exceptional conditions that could stem from exploited weaknesses. |
SI-13 | Predictable Failure Prevention | SI | Prepared component exchange provides a defined recovery path, making improper handling of failures less exploitable. |
SI-17 | Fail-safe Procedures | SI | Mandates defined procedures that ensure exceptional conditions are handled in a controlled, secure manner instead of being ignored or mishandled. |
AU-5 | Response to Audit Logging Process Failures | AU | Provides defined handling (alert and additional actions) for the exceptional condition of audit logging failure. |
SC-24 | Fail in Known State | SC | Enforces structured response to exceptional conditions so the system cannot remain in an unsafe state. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2017-5638 KEV UPD | 9.9 | 9.8 | 1.0000 | 2017-03-11 |
CVE-2020-7247 KEV UPD | 9.9 | 9.8 | 0.9897 | 2020-01-29 |
CVE-2019-12815 UPD | 9.5 | 9.8 | 0.5761 | 2019-07-19 |
CVE-2021-38003 KEV UPD | 9.2 | 8.8 | 0.3857 | 2021-11-23 |
CVE-2019-14287 UPD | 8.9 | 8.8 | 0.6376 | 2019-10-17 |
CVE-2018-0155 KEV UPD | 8.8 | 8.6 | 0.0779 | 2018-03-28 |
CVE-2024-29748 KEV UPD | 8.5 | 7.8 | 0.0068 | 2024-04-05 |
CVE-2023-36933 UPD | 8.4 | 7.5 | 0.7224 | 2023-07-05 |
CVE-2019-17195 UPD | 8.2 | 9.8 | 0.1103 | 2019-10-15 |
CVE-2018-0934 UPD | 8.1 | 7.5 | 0.6676 | 2018-03-14 |
CVE-2022-23121 UPD | 8.1 | 9.8 | 0.0859 | 2023-03-28 |
CVE-2021-28165 UPD | 8.0 | 7.5 | 0.5386 | 2021-04-01 |
CVE-2019-14431 UPD | 7.8 | 9.8 | 0.0363 | 2019-07-29 |
CVE-2019-6848 UPD | 7.8 | 8.6 | 0.3297 | 2019-10-29 |
CVE-2021-43272 UPD | 7.8 | 9.8 | 0.0352 | 2021-11-14 |
CVE-2021-40391 UPD | 7.8 | 9.8 | 0.0289 | 2021-11-19 |
CVE-2017-2877 UPD | 7.7 | 9.8 | 0.0190 | 2018-09-19 |
CVE-2018-19991 UPD | 7.7 | 9.8 | 0.0233 | 2018-12-10 |
CVE-2019-6256 UPD | 7.7 | 9.8 | 0.0241 | 2019-01-14 |
CVE-2019-14378 UPD | 7.7 | 8.8 | 0.1666 | 2019-07-29 |
CVE-2020-24753 UPD | 7.7 | 9.8 | 0.0264 | 2020-09-17 |
CVE-2022-31799 UPD | 7.7 | 9.8 | 0.0205 | 2022-06-02 |
CVE-2021-36128 UPD | 7.6 | 9.8 | 0.0150 | 2021-07-02 |
CVE-2021-38384 UPD | 7.6 | 9.8 | 0.0146 | 2021-08-10 |
CVE-2022-48328 UPD | 7.6 | 9.8 | 0.0130 | 2023-02-20 |