CWE-410
20 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-410page 1 of 1
- CVE-2018-13815HIGHCVSS 7.5EG 7.52018-12-13
A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected device by opening a sufficient number of connections to th…
- CVE-2019-0056HIGHCVSS 7.5EG 7.52019-10-09
This issue only affects devices with three (3) or more MPC10's installed in a single chassis with OSPF enabled and configured on the device. An Insufficient Resource Pool weakness allows an attacker to cause the device's Open Shortest Path…
- CVE-2019-13921HIGHCVSS 7.5EG 7.52019-10-10
A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain a vulnerability that could allow an unauthenticated attacker to trigger a denial-of-service conditio…
- CVE-2021-1615HIGHCVSS 8.6EG 8.62021-09-23
A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an…
- CVE-2022-2048HIGHCVSS 7.5EG 7.52022-07-07
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial o…
- CVE-2022-20937MEDIUMCVSS 5.3EG 5.32022-11-04
A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability i…
- CVE-2022-22191MEDIUMCVSS 6.5EG 6.52022-04-14
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent from the local broadcast domain, may allow an unauthenticated network-adjacent attacker to…
- CVE-2022-40224HIGHCVSS 7.5EG 7.52023-02-07
A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to…
- CVE-2022-46679MEDIUMCVSS 6.5EG 7.52023-02-01
Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
- CVE-2023-38505HIGHCVSS 7.5EG 7.52023-07-27
DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to be in process at a given moment. Once a TCP connection is established in HTTPS mode, it will assume that it should be w…
- CVE-2023-7033MEDIUMCVSS 5.3EG 5.32024-02-27
Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface Module, MELSEC iQ-R CC-Link IE TSN Master/Local M…
- CVE-2024-7392MEDIUMCVSS 6.5EG 4.32024-11-22
ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. A…
- CVE-2025-0453HIGHCVSS 7.5EG 5.92025-03-20
In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers…
- CVE-2025-12986MEDIUMCVSS 6.0EG 0.02025-12-04
When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service triggered by a malformed packet. The device may recover automatically or require a hard reset.
- CVE-2025-20103MEDIUMCVSS 6.5EG 6.52025-05-13
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2025-2134LOWCVSS 3.5EG 3.52026-02-04
IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.
- CVE-2025-27479HIGHCVSS 7.5EG 7.52025-04-08
Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
- CVE-2025-27694MEDIUMCVSS 5.3EG 5.32025-04-02
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
- CVE-2025-41653HIGHCVSS 7.5EG 7.52025-05-27
An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted HTTP request with a malicious header, potentially causing the server to crash or becom…
- CVE-2026-34019MEDIUMCVSS 5.3EG 5.32026-05-13
When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing pro…
Map vulnerabilities like CWE-410 to your infrastructure
EchelonGraph correlates every CVE — across CWE-410 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →