CWE · MITRE source
CWE-405Asymmetric Resource Consumption (Amplification)
The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."
This can lead to poor performance due to "amplification" of resource consumption, typically in a non-linear fashion. This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.
Last updated: 11 August 2026 14:55 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 6 mapping(s) from 3 framework(s): STIG oracle linux 8 2 (mostly) · STIG oracle linux 9 2 (mostly) · STIG rhel 8 2 (partial)
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
DE.CM-01DE.CM-09
- 6 hardening rules · 3 OS baselines
—
NIST 800-53 r5 controls that address this weakness (5)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-47 | Alternate Communications Paths | SC | Amplification attacks that exhaust the primary path are mitigated by the existence of an independent alternate path for command traffic. |
SC-5 | Denial-of-service Protection | SC | Employs controls that mitigate amplification attacks causing asymmetric resource use. |
SC-6 | Resource Availability | SC | Limits amplification effects by controlling how resources are allocated under high-volume or recursive load. |
CP-7 | Alternate Processing Site | CP | Reduces impact of amplification attacks that overwhelm the primary site by allowing operations to shift to an equivalent alternate site. |
CP-8 | Telecommunications Services | CP | Alternate services reduce the impact of amplification attacks that exhaust primary telecommunications resources. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2019-11479 UPD | 8.5 | 7.5 | 0.9166 | 2019-06-19 |
CVE-2025-53633 UPD | 7.3 | 9.8 | 0.0046 | 2025-07-10 |
CVE-2021-38447 UPD | 6.9 | 8.6 | 0.0205 | 2022-05-05 |
CVE-2024-11187 UPD | 6.9 | 7.5 | 0.1547 | 2025-01-29 |
CVE-2025-8677 UPD | 6.8 | 7.5 | 0.1120 | 2025-10-22 |
CVE-2024-56200 UPD | 6.3 | 8.6 | 0.0059 | 2024-12-19 |
CVE-2018-15492 UPD | 6.1 | 7.5 | 0.0121 | 2018-08-18 |
CVE-2024-45590 UPD | 6.0 | 7.5 | 0.0082 | 2024-09-10 |
CVE-2024-55628 UPD | 6.0 | 7.5 | 0.0069 | 2025-01-06 |
CVE-2026-25611 UPD | 6.0 | 7.5 | 0.0078 | 2026-02-10 |
CVE-2026-47774 UPD | 6.0 | 7.5 | 0.0097 | 2026-06-17 |
CVE-2023-2992 UPD | 5.9 | 7.5 | 0.0062 | 2023-06-26 |
CVE-2024-34703 UPD | 5.9 | 7.5 | 0.0050 | 2024-06-30 |
CVE-2025-24356 UPD | 5.9 | 7.5 | 0.0066 | 2025-01-27 |
CVE-2025-30204 UPD | 5.9 | 7.5 | 0.0069 | 2025-03-21 |
CVE-2025-22166 UPD | 5.9 | 7.5 | 0.0047 | 2025-10-21 |
CVE-2026-22774 UPD | 5.9 | 7.5 | 0.0057 | 2026-01-15 |
CVE-2026-22775 UPD | 5.9 | 7.5 | 0.0057 | 2026-01-15 |
CVE-2025-66564 UPD | 5.8 | 7.5 | 0.0045 | 2025-12-04 |
CVE-2026-0485 UPD | 5.8 | 7.5 | 0.0040 | 2026-02-10 |
CVE-2026-72914 | 5.8 | 7.5 | 0.0045 | 2026-08-10 |
CVE-2025-66506 UPD | 5.7 | 7.5 | 0.0021 | 2025-12-04 |
CVE-2025-42874 UPD | 5.7 | 7.9 | 0.0046 | 2025-12-09 |
CVE-2026-44296 UPD | 5.7 | 7.5 | 0.0028 | 2026-05-12 |
CVE-2024-49363 UPD | 5.4 | 7.4 | 0.0031 | 2024-12-18 |