CWE Database
/

CWE-408

Back to CWE list

CWE-408

Incorrect Behavior Order: Early Amplification

Base
Draft

Description

The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.

Common Consequences

Scope

Availability

Impact

DoS: Amplification, DoS: Crash, Exit, or Restart, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory)

CVE-2004-2458

Tool creates directories before authenticating user.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now