{"id":"CVE-2025-8352","title":"Allocation of resources without limits or throttling vulnerability in ESET PROTECT On-Prem increased resource consumption (CPU and RAM), leading to conditions for a Denial-of-Service attack.","summary":"Allocation of resources without limits or throttling vulnerability in ESET PROTECT On-Prem increased resource consumption (CPU and RAM), leading to conditions for a Denial-of-Service attack.","severity":"medium","cvss":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-770"],"vendor":"ESET spol. s.r.o","product":"ESET PROTECT On-Prem","affected":["eset_protect_on-prem <= 12.1.9.0 (with Web Console 12.1.252.0)","eset_protect_on-prem <= 12.0.13.0  (with Web Console 12.0.289.0)","eset_protect_on-prem <= 11.1.16.0  (with Web Console 11.1.149.0)"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T16:00:36.547","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-8352","references":[{"url":"https://support.eset.com/en/ca8854-eset-customer-advisory-denial-of-service-vulnerability-in-eset-protect-on-prem-fixed","label":"security@eset.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-06T15:01:49.296Z","slug":"CVE-2025-8352","body":"## Overview\n\nAllocation of resources without limits or throttling vulnerability in ESET PROTECT On-Prem increased resource consumption (CPU and RAM), leading to conditions for a Denial-of-Service attack.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":38,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}