CWE-440Base

Expected Behavior Violation

Draft in the CWE catalog · 43 CVEs mapped

43
CVEs mapped
5.5
Median CVSS
What it is

A feature, API, or function does not perform according to its specification.

Recent examples
none
CVE-2026-65934

CVE-2026-65934 - UNKNOWN Severity Vulnerability

An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.  See vulnerability B-E10 in the related paper below.

no explanation yet
0%
epss
none
CVE-2026-65932

CVE-2026-65932 - UNKNOWN Severity Vulnerability

The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.

no explanation yet
0%
epss
8.7cvss
CVE-2026-8806

Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module

Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication packets to the Ethernet port of the product in a short period of time, increasing the processing load of the product, preventing the internal anomaly-detection processing from being performed, and causing the communication function to stop.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-440
Abstraction
Base
Structure
Simple
Status
Draft
References (3)