CWE-406

Insufficient Control of Network Message Volume (Network Amplification)

Medium

Description

The product does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the product to transmit more traffic than should be allowed for that actor.

Potential Impact

How to Fix

Architecture and Design

An application must make network resources available to a client commensurate with the client's access level.

Policy

Define a clear policy for network resource allocation and consumption.

Implementation

An application must, at all times, keep track of network resources and meter their usage appropriately.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-406 vulnerabilities in your codebase.

Get Security Assessment