Cyber Resilience

CWE · MITRE source

CWE-405Asymmetric Resource Consumption (Amplification)

Abstraction: Class · CVEs in our corpus: 47

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

This can lead to poor performance due to "amplification" of resource consumption, typically in a non-linear fashion. This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.

Last updated: 11 August 2026 14:55 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 6 mapping(s) from 3 framework(s): STIG oracle linux 8 2 (mostly) · STIG oracle linux 9 2 (mostly) · STIG rhel 8 2 (partial)

See the full cumulative-coverage rollup →

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-47 Alternate Communications Paths
  • SC-5 Denial-of-service Protection
  • SC-6 Resource Availability
  • CP-7 Alternate Processing Site
Detect
Catch it (CSF Detect / Respond)
  • DE.CM-01
  • DE.CM-09
Harden
Shrink the surface (DISA STIG)
  • 6 hardening rules · 3 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (5)AI-assisted

Control Title Family Why it addresses this CWE
SC-47Alternate Communications PathsSCAmplification attacks that exhaust the primary path are mitigated by the existence of an independent alternate path for command traffic.
SC-5Denial-of-service ProtectionSCEmploys controls that mitigate amplification attacks causing asymmetric resource use.
SC-6Resource AvailabilitySCLimits amplification effects by controlling how resources are allocated under high-volume or recursive load.
CP-7Alternate Processing SiteCPReduces impact of amplification attacks that overwhelm the primary site by allowing operations to shift to an equivalent alternate site.
CP-8Telecommunications ServicesCPAlternate services reduce the impact of amplification attacks that exhaust primary telecommunications resources.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-11479 8.57.50.91662019-06-19
CVE-2025-53633 7.39.80.00462025-07-10
CVE-2021-38447 6.98.60.02052022-05-05
CVE-2024-11187 6.97.50.15472025-01-29
CVE-2025-8677 6.87.50.11202025-10-22
CVE-2024-56200 6.38.60.00592024-12-19
CVE-2018-15492 6.17.50.01212018-08-18
CVE-2024-45590 6.07.50.00822024-09-10
CVE-2024-55628 6.07.50.00692025-01-06
CVE-2026-25611 6.07.50.00782026-02-10
CVE-2026-47774 6.07.50.00972026-06-17
CVE-2023-2992 5.97.50.00622023-06-26
CVE-2024-34703 5.97.50.00502024-06-30
CVE-2025-24356 5.97.50.00662025-01-27
CVE-2025-30204 5.97.50.00692025-03-21
CVE-2025-22166 5.97.50.00472025-10-21
CVE-2026-22774 5.97.50.00572026-01-15
CVE-2026-22775 5.97.50.00572026-01-15
CVE-2025-66564 5.87.50.00452025-12-04
CVE-2026-0485 5.87.50.00402026-02-10
CVE-2026-729145.87.50.00452026-08-10
CVE-2025-66506 5.77.50.00212025-12-04
CVE-2025-42874 5.77.90.00462025-12-09
CVE-2026-44296 5.77.50.00282026-05-12
CVE-2024-49363 5.47.40.00312024-12-18