Falhas do tipo CWE-410

21 resultados

Pool de recursos insuficiente

A aplicação aloca um número fixo e pequeno de recursos (conexões de banco, threads, memória) sem crescimento dinâmico ou limite de espera adequado. Quando a demanda excede a capacidade, requisições legítimas são rejeitadas ou falham, causando negação de serviço (DoS) mesmo sem ataque malicioso.

Exemplo

Um servidor web com pool de apenas 10 conexões de banco de dados atende 100 usuários simultâneos. Após 10 conexões estarem em uso, as demais requisições travam ou caem porque não há recurso disponível e nenhuma fila aguarda liberação.

Como mitigar

Dimensione o pool conforme pico de carga real (testes de capacidade), implemente fila de espera com timeout e monitore ocupação. Use auto-scaling em infraestrutura ou circuit breaker para degradar graciosamente antes do colapso.

CVE-2022-40224MEDIUMA denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A speciallyEPSS 64.7%CVE-2025-0453MEDIUMDenial of Service through Batched Queries in GraphQL in mlflow/mlflowEPSS 10.4%CVE-2022-2048HIGHIn Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up noEPSS 2.3%CVE-2025-27479HIGHKerberos Key Distribution Proxy Service Denial of Service VulnerabilityEPSS 2.0%CVE-2018-13815A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the EPSS 1.8%CVE-2019-13921A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain aEPSS 1.4%CVE-2021-1615HIGHCisco Embedded Wireless Controller Software for Catalyst Access Points Denial of Service VulnerabilityEPSS 1.3%CVE-2019-0056HIGHJunos OS: MX Series: An MPC10 Denial of Service (DoS) due to OSPF states transitioning to Down, causes traffic to stop forwarding through the device.EPSS 1.3%CVE-2026-58218MEDIUMSamba: dns signing dos via tkey name cache exhaustionEPSS 1.1%CVE-2023-7033MEDIUMInsufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L EPSS 0.9%CVE-2022-20937MEDIUMA vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, EPSS 0.8%CVE-2023-38505HIGHDietPi-Dashboard Insufficient TLS Handshake PoolEPSS 0.8%CVE-2022-46679MEDIUM Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker coulEPSS 0.8%CVE-2024-7392MEDIUMChargePoint Home Flex Bluetooth Low Energy Denial-of-Service VulnerabilityEPSS 0.5%CVE-2025-41653HIGHWeidmueller: Denial-of-Service Vulnerability in the web server functionality of Industrial Ethernet SwitchesEPSS 0.5%CVE-2025-27694MEDIUMDell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker wiEPSS 0.4%CVE-2022-22191MEDIUMJunos OS: EX4300: PFE Denial of Service (DoS) upon receipt of a flood of specific ARP trafficEPSS 0.4%CVE-2026-34019MEDIUMBIG-IP BFD vulnerabilityEPSS 0.3%CVE-2025-2134LOWIBM Jazz Reporting Service Denial of ServiceEPSS 0.2%CVE-2025-12986MEDIUMDenial of Service Vulnerability in Silicon Labs WF200 and WGM160P DevicesEPSS 0.2%