Falhas do tipo CWE-406

19 resultados

Amplificação de Tráfego de Rede

É quando uma aplicação responde a requisições pequenas com respostas muito maiores, permitindo que um atacante use servidores legítimos como amplificadores em ataques DDoS. O problema: não há limite ou validação adequada no volume de dados enviado em resposta, transformando o servidor em arma contra outras vítimas.

Exemplo

Um serviço DNS ou NTP mal configurado que responde a requisições UDP simples com pacotes enormes; um atacante falsifica o IP de origem apontando para a vítima, e o servidor amplifica o ataque enviando megabytes em resposta a cada byte recebido.

Como mitigar

Implemente rate limiting por IP origem, valide e limite o tamanho das respostas, desabilite reflexão em protocolos como DNS/NTP (usando ACLs), e monitore padrões anormais de tráfego de saída. Em APIs, autentique requisições e applique quotas de resposta.

CVE-2021-38425HIGHeProsima Fast DDS Network AmplificationEPSS 5.0%CVE-2021-38487HIGHPotential Network Amplification and Information Exposure in RTI Connext Professional and Connext MicroEPSS 3.3%CVE-2021-43547HIGHTwinOaks Computing CoreDX DDS Secure Network AmplificationEPSS 2.4%CVE-2022-0028HIGHPAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL FilteringEPSS 2.4%KEVCVE-2019-14850A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and caEPSS 1.6%CVE-2021-38429MEDIUMOCI OpenDDS Secure Network AmplificationEPSS 1.4%CVE-2020-10772An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable veEPSS 1.3%CVE-2024-25015HIGHIBM MQ denial of serviceEPSS 0.9%CVE-2021-4234OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the clEPSS 0.9%CVE-2023-49203HIGHTechnitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb manipulation causes accEPSS 0.6%CVE-2023-28456HIGHAn issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more than other "golden EPSS 0.5%CVE-2023-28455HIGHAn issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using Technitium resolverEPSS 0.5%CVE-2021-38135HIGHPossible External service interaction Vulnerability in OpenText iManagerEPSS 0.4%CVE-2026-68080MEDIUMApache Qpid Broker-J: Unbounded echo flow responses can lead to denial of serviceEPSS 0.4%CVE-2014-125036LOWdrybjed ansible-ntp main.yml amplificationEPSS 0.4%CVE-2026-45557MEDIUMTechnitium DNS Server excessive DNSSEC requestsEPSS 0.4%CVE-2025-58066MEDIUMDoS Vulnerability in ntpd-rsEPSS 0.3%CVE-2026-50045MEDIUM'max-global-quota' reset by DNSSEC validation restartsEPSS 0.3%CVE-2026-54609HIGHQTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingEPSS 0.3%