VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 5 of 191
  • CVE-2025-10470HigMay 11, 2026
    risk 0.56cvss 8.6epss 0.00

    The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability…

  • CVE-2026-20084HigMar 25, 2026
    risk 0.56cvss 8.6epss 0.00

    A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of…

  • CVE-2025-20162HigMay 7, 2025
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition. This vulnerability is due to improper handling of…

  • CVE-2023-20125HigNov 15, 2024
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting does not occur for certain…

  • CVE-2024-20351HigOct 23, 2024
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be dropped, resulting in a…

  • CVE-2024-20321HigFeb 29, 2024
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because eBGP traffic is mapped…

  • CVE-2023-48297HigJan 12, 2024
    risk 0.56cvss 8.6epss 0.01

    Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

  • CVE-2023-20259HigOct 4, 2023
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is…

  • CVE-2023-21547HigJan 10, 2023
    risk 0.56cvss 7.5epss 0.89

    Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

  • CVE-2022-20760HigMay 3, 2022
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is…

  • CVE-2021-40117HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This…

  • CVE-2021-34792HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due…

  • CVE-2021-41145HigOct 25, 2021
    risk 0.56cvss 8.6epss 0.02

    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is susceptible to Denial of Service via SIP flooding. When…

  • CVE-2020-28450HigFeb 4, 2021
    risk 0.56cvss 8.6epss 0.02

    This affects all versions of package decal. The vulnerability is in the extend function.

  • CVE-2020-28449HigFeb 4, 2021
    risk 0.56cvss 8.6epss 0.02

    This affects all versions of package decal. The vulnerability is in the set function.

  • CVE-2021-25909HigJan 29, 2021
    risk 0.56cvss 8.6epss 0.01

    ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending specific packets to the port 7919.

  • CVE-2020-3572HigOct 21, 2020
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The…

  • CVE-2020-3571HigOct 21, 2020
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due…

  • CVE-2020-3563HigOct 21, 2020
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management.…

  • CVE-2020-3533HigOct 21, 2020
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly. The vulnerability is due to a lack of…