← All CVEs

CVE-2019-9515

high · 7.5

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

7.5
CVSS
87.4%
EPSS (exploit prob.)
100th
EPSS percentile
2019-08-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-400CWE-770

Affected products

VendorProductAffected versions
appleswiftnio>= 1.0.0, <= 1.4.0
applemac_os_x>= 10.12
canonicalubuntu_linux>= 14.04
apachetraffic_server>= 6.0.0, <= 6.2.3
apachetraffic_server>= 7.0.0, <= 7.1.6
apachetraffic_server>= 8.0.0, <= 8.0.3
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux19.04
debiandebian_linux9.0
debiandebian_linux10.0
synologyskynasall versions
synologydiskstation_manager6.2
synologyvs960hd_firmwareall versions
synologyvs960hdall versions
fedoraprojectfedora29
fedoraprojectfedora30
opensuseleap15.0
opensuseleap15.1
redhatjboss_core_services1.0
redhatjboss_enterprise_application_platform7.2.0
redhatjboss_enterprise_application_platform7.3.0
redhatopenshift_container_platform4.1
redhatopenshift_service_mesh1.0
redhatopenstack14
redhatquay3.0.0
redhatsingle_sign-on7.3
redhatsoftware_collections1.0
redhatenterprise_linux8.0
oraclegraalvm19.2.0
mcafeeweb_gateway>= 7.7.2.0, < 7.7.2.24
mcafeeweb_gateway>= 7.8.2.0, < 7.8.2.13
mcafeeweb_gateway>= 8.1.0, < 8.2.0
f5big-ip_local_traffic_manager>= 11.6.1, < 11.6.5.1
f5big-ip_local_traffic_manager>= 12.1.0, < 12.1.5.1
f5big-ip_local_traffic_manager>= 13.1.0, < 13.1.3.2
f5big-ip_local_traffic_manager>= 14.0.0, < 14.0.1.1
f5big-ip_local_traffic_manager>= 14.1.0, < 14.1.2.1
f5big-ip_local_traffic_manager>= 15.0.0, < 15.0.1.1
nodejsnode.js>= 8.0.0, <= 8.8.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-9515