Skip to main content

About CWE-399

As a Category it has no consequences of its own; impacts depend on the member weakness. For resource exhaustion, MITRE lists denial of service as the most common result.

MITRE marks CWE-399 as PROHIBITED for mapping real-world vulnerabilities because it is a Category; weakness-level alternatives may be found under CWE-400.

MITRE name
Resource Management Errors
Abstraction
Category: a structural grouping of entries that share a characteristic, not a weakness itself
Status
Draft

Mitigations

  • +Map each vulnerability to a specific weakness, for example a descendant of Uncontrolled Resource Consumption (CWE-400).
  • +Set per-user limits on resources that unprivileged users can consume, and let administrators adjust them (CWE-770).
  • +Design throttling into the architecture and track request rates to block clients that exceed thresholds (CWE-770).
  • +Ensure every failed resource allocation leaves the system in a safe state (CWE-400).

CWE-399 Vulnerabilities

10 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2018-0156
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
-7.59.4%KEV2018-03-28
CVE-2017-12231
Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
-7.57.1%KEV2017-09-28
CVE-2017-12237
Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
-7.57.1%KEV2017-09-28
CVE-2018-0154
Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability
-7.57.1%KEV2018-03-28
CVE-2017-6627
Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
-7.56.2%KEV2017-09-07
CVE-2018-0179
Cisco IOS Software Denial-of-Service Vulnerability
-6.84.9%KEV2018-03-28
CVE-2018-0180
Cisco IOS Software Denial-of-Service Vulnerability
-6.84.9%KEV2018-03-28
CVE-2018-0161
Cisco IOS Software Resource Management Errors Vulnerability
-6.34.1%KEV2018-03-28
CVE-2017-12232
Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
-6.52.2%KEV2017-09-28
CVE-2017-12238
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
-6.52.0%KEV2017-09-28

Most Affected Vendors

Frequently Asked Questions

What is CWE-399?→

CWE-399 is a MITRE Category named Resource Management Errors. It is an organizational grouping, not a weakness.

Why do some CVEs still list CWE-399?→

MITRE says the ID became widely used because NVD used it from 2008 to 2016. Mapping to categories has been discouraged since 2019 and is now prohibited for this entry.

How many exploited vulnerabilities are classified as CWE-399?→

This database lists 10 CVE records mapped to CWE-399 by their CVE Numbering Authority. 10 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2018-0156, CVE-2017-12231, CVE-2017-12237.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.