Apparently 1/3 of all software vulnerabilities represent design weaknesses which were introduced in the requirements phase. The MCAS flaw seems to belong to this category which you describe.
source: https://insights.sei.cmu.edu/blog/a-tool-to-address-cybersec...