Weaknesses of type CWE-406

19 results

Amplificação de Tráfego de Rede

Fraqueza onde um atacante envia poucos pacotes para um servidor, que responde com muito mais dados, amplificando o tráfego original. Geralmente explorada em ataques DDoS (distributed denial of service) onde o servidor intermediário é usado como arma para sobrecarregar a vítima real.

Example

Um servidor DNS mal configurado responde com respostas massivas a queries simples; um atacante envia requisições falsificadas (spoofing) com IP da vítima, fazendo o DNS enviar gigabytes de dados para ela. Um pacote pequeno gera resposta 10-50 vezes maior, multiplicando o dano.

How to mitigate

Implemente rate limiting e validação de origem (verificar se o IP de origem é legítimo antes de responder); desabilite respostas a queries recursivas de IPs externos; monitore e filtre pacotes com spoofing de IP; use ACLs e firewalls para limitar quem pode fazer requisições amplificadas ao seu servidor.

CVE-2021-38425HIGHeProsima Fast DDS Network AmplificationEPSS 5.0%CVE-2021-38487HIGHPotential Network Amplification and Information Exposure in RTI Connext Professional and Connext MicroEPSS 3.3%CVE-2021-43547HIGHTwinOaks Computing CoreDX DDS Secure Network AmplificationEPSS 2.4%CVE-2022-0028HIGHPAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL FilteringEPSS 2.4%KEVCVE-2019-14850A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and caEPSS 1.6%CVE-2021-38429MEDIUMOCI OpenDDS Secure Network AmplificationEPSS 1.4%CVE-2020-10772An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable veEPSS 1.3%CVE-2024-25015HIGHIBM MQ denial of serviceEPSS 0.9%CVE-2021-4234OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the clEPSS 0.9%CVE-2023-49203HIGHTechnitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb manipulation causes accEPSS 0.6%CVE-2023-28456HIGHAn issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more than other "golden EPSS 0.5%CVE-2023-28455HIGHAn issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using Technitium resolverEPSS 0.5%CVE-2021-38135HIGHPossible External service interaction Vulnerability in OpenText iManagerEPSS 0.4%CVE-2026-68080MEDIUMApache Qpid Broker-J: Unbounded echo flow responses can lead to denial of serviceEPSS 0.4%CVE-2014-125036LOWdrybjed ansible-ntp main.yml amplificationEPSS 0.4%CVE-2026-45557MEDIUMTechnitium DNS Server excessive DNSSEC requestsEPSS 0.4%CVE-2025-58066MEDIUMDoS Vulnerability in ntpd-rsEPSS 0.3%CVE-2026-50045MEDIUM'max-global-quota' reset by DNSSEC validation restartsEPSS 0.3%CVE-2026-54609HIGHQTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingEPSS 0.3%