CWE-369: Divide By Zero
The product divides a value by zero.
How it's found
Divide By Zero is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
This weakness typically occurs when an unexpected value is provided to the product, or if an error occurs that is not properly detected. It frequently occurs in calculations involving physical dimensions such as size, length, width, and height.
Vulnerable vs. safe
return totalTime / numRequests;public int computeAverageResponseTime (int totalTime, int numRequests) {}System.out.println("Division by zero attempted!");throw ArithmeticException;
if (numRequests == 0) {}return totalTime / numRequests;public int computeAverageResponseTime (int totalTime, int numRequests) throws ArithmeticException {}Consequences
- DoS: Crash, Exit, or Restart: A Divide by Zero results in a crash.
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is CWE-369?
The product divides a value by zero.
How do you find Divide By Zero?
Divide By Zero is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
What is the impact of CWE-369?
DoS: Crash, Exit, or Restart: A Divide by Zero results in a crash.
Does TurboPentest test for Divide By Zero?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related CWEs
- Pillar weaknessCWE-682: Incorrect Calculation
- Variant weaknessCWE-48: Path Equivalence: 'file name' (Internal Whitespace)
- Base weaknessCWE-170: Improper Null Termination
- Variant weaknessCWE-382: J2EE Bad Practices: Use of System.exit()
- Class weaknessCWE-400: Uncontrolled Resource Consumption
- Variant weaknessCWE-401: Missing Release of Memory after Effective Lifetime
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest