VYPR

CWE-410

Insufficient Resource Pool

ClassIncomplete

Description

The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.

Frequently the consequence is a "flood" of connection or sessions.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (21)

page 1 of 2
  • CVE-2021-1615HigSep 23, 2021
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due…

  • CVE-2022-40224HigFeb 7, 2023
    risk 0.54cvss 7.5epss 0.65

    A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2025-41653HigMay 27, 2025
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted HTTP request with a malicious header, potentially causing the server to crash or become unresponsive.

  • CVE-2025-27479HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.

  • CVE-2025-0453HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.10

    In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the…

  • CVE-2022-2048HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no…

  • CVE-2019-13921HigOct 10, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain a vulnerability that could allow an unauthenticated attacker to trigger a denial-of-service condition. The vulnerability can be triggered if…

  • CVE-2019-0056HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.01

    This issue only affects devices with three (3) or more MPC10's installed in a single chassis with OSPF enabled and configured on the device. An Insufficient Resource Pool weakness allows an attacker to cause the device's Open Shortest Path First (OSPF) states to transition to…

  • CVE-2018-13815HigDec 13, 2018
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected device by opening a sufficient number of connections to the device. Successful exploitation…

  • CVE-2025-20103MedMay 13, 2025
    risk 0.42cvss 6.5epss 0.00

    Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2024-7392MedNov 22, 2024
    risk 0.42cvss 6.5epss 0.01

    ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit…

  • CVE-2022-46679MedFeb 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2022-22191MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.00

    A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent from the local broadcast domain, may allow an unauthenticated network-adjacent attacker to trigger a PFEMAN watchdog timeout,…

  • CVE-2025-12986MedDec 4, 2025
    risk 0.39cvss epss 0.00

    When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service triggered by a malformed packet. The device may recover automatically or require a hard reset.

  • CVE-2026-58218MedJul 30, 2026
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names,…

  • CVE-2023-7033MedFeb 27, 2024
    risk 0.35cvss 5.3epss 0.01

    Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface Module, MELSEC iQ-R CC-Link IE TSN Master/Local Module, CC-Link IE TSN Remote I/O Module,…

  • CVE-2022-20937MedNov 4, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of…

  • CVE-2026-34019MedMay 13, 2026
    risk 0.34cvss 5.3epss 0.00

    When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over.  Note: Software…

  • CVE-2025-27694MedApr 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2025-2134LowFeb 4, 2026
    risk 0.23cvss 3.5epss 0.00

    IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.