NIST SP 800-53 Rev. 5 · System and Information Integrity
SI-2 — Flaw Remediation
Known-exploited vulnerability past its remediation date. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.
Why this matters
A machine still exposed to a break-in method attackers are using today
The U.S. Cybersecurity and Infrastructure Security Agency maintains a public catalogue of software flaws that criminals are confirmed to be exploiting right now, and it publishes a deadline by which federal agencies must fix each one. The catalogue is free and authoritative, but an organization still has to work out whether any of those flaws are present on its own machines, and whether the deadline has passed. A small utility or clinic with no security staff has no practical way to answer that.
Why this check earns its place. This is the highest-value check in the collection because the flaws are not theoretical. Each one is on the list precisely because attacks using it have been observed.
- What it reads
- The organization's own vulnerability scan results, cross-referenced against the federal catalogue.
- What it reports
- Machines still carrying a flaw from the federal catalogue after the date by which it was supposed to be fixed.
See related public disclosures on the Signals page →
The requirement
The organization must identify, report, and correct information system flaws, and install security-relevant updates within an organization-defined time period of their release.
NIST SP 800-53 Rev. 5 — SI-2 (Flaw Remediation).
NIST requires flaws to be corrected within a period the organization defines. This pack does not attempt to judge every CVE. It narrows to CISA's Known Exploited Vulnerabilities catalogue — the subset with confirmed exploitation in the wild — and reports the ones still present after the remediation date CISA published. Which asset population is in scope, and whether a compensating control justifies an exception, remain organization-defined.
What a check finds
An asset still reports an active finding for a CVE in CISA's Known Exploited Vulnerabilities catalogue, after the remediation date CISA published for that entry.
Choose your platform
CISA performance goals
- 2.B — Mitigate known vulnerabilities
- 2.A — Manage organizational assets (partial)
What a result does not prove
A KEV entry past its due date does not establish that the vulnerability was exploited in your environment, or that exploitation is possible given your configuration. It establishes that a vulnerability confirmed to be exploited elsewhere is still reported as present after the date the federal catalogue set for fixing it. Scanner coverage gaps mean the absence of rows is not evidence of the absence of the condition.