CVE-2023-44487
high · 7.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Added 2023-10-10Remediation due 2023-10-31
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2023-10-10
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| siemens | simatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware | >= 3.1.5 |
| siemens | simatic_s7-1500_cpu_1518f-4_pn/dp_mfp | all versions |
| siemens | sinec_ins | < 1.0 |
| siemens | sinec_ins | 1.0 |
| siemens | sinec_ins | 1.0 |
| siemens | sinec_ins | 1.0 |
| siemens | sinec_ins | 1.0 |
| siemens | sinec_ins | 1.0 |
| siemens | sinec_nms | < 3.0 |
| siemens | st7_scadaconnect | < 1.1 |
| siemens | ruggedcom_ape1808_firmware | all versions |
| siemens | ruggedcom_ape1808 | all versions |
| siemens | simatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware | >= 3.1.5 |
| siemens | simatic_s7-1500_cpu_1518-4_pn/dp | all versions |
| siemens | siplus_s7-1500_cpu_1518-4_pn/dp_mfp_firmware | >= 3.1.5 |
| siemens | siplus_s7-1500_cpu_1518-4_pn/dp_mfp | all versions |
| ietf | http | 2.0 |
| nghttp2 | nghttp2 | < 1.57.0 |
| netty | netty | < 4.1.100 |
| envoyproxy | envoy | 1.24.10 |
| envoyproxy | envoy | 1.25.9 |
| envoyproxy | envoy | 1.26.4 |
| envoyproxy | envoy | 1.27.0 |
| eclipse | jetty | < 9.4.53 |
| eclipse | jetty | >= 10.0.0, < 10.0.17 |
| eclipse | jetty | >= 11.0.0, < 11.0.17 |
| eclipse | jetty | >= 12.0.0, < 12.0.2 |
| caddyserver | caddy | < 2.7.5 |
| golang | go | < 1.20.10 |
| golang | go | >= 1.21.0, < 1.21.3 |
| golang | http2 | < 0.17.0 |
| golang | networking | < 0.17.0 |
| f5 | big-ip_access_policy_manager | >= 13.1.0, <= 13.1.5 |
| f5 | big-ip_access_policy_manager | >= 14.1.0, <= 14.1.5 |
| f5 | big-ip_access_policy_manager | >= 15.1.0, <= 15.1.10 |
| f5 | big-ip_access_policy_manager | >= 16.1.0, <= 16.1.4 |
| f5 | big-ip_access_policy_manager | 17.1.0 |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0, <= 13.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0, <= 14.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0, <= 15.1.10 |
Check a specific version with /api/v1/cve/match.
References
- http://www.openwall.com/lists/oss-security/2023/10/10/6
- http://www.openwall.com/lists/oss-security/2023/10/10/7
- http://www.openwall.com/lists/oss-security/2023/10/13/4
- http://www.openwall.com/lists/oss-security/2023/10/13/9
- http://www.openwall.com/lists/oss-security/2023/10/18/4
- http://www.openwall.com/lists/oss-security/2023/10/18/8
- http://www.openwall.com/lists/oss-security/2023/10/19/6
- http://www.openwall.com/lists/oss-security/2023/10/20/8
- https://access.redhat.com/security/cve/cve-2023-44487
- https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/
- https://aws.amazon.com/security/security-bulletins/AWS-2023-011/
- https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
- https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
- https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
- https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack
- https://blog.vespa.ai/cve-2023-44487/
- https://bugzilla.proxmox.com/show_bug.cgi?id=4988
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803
- https://bugzilla.suse.com/show_bug.cgi?id=1216123
- https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9
- https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
- https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack
- https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125
- https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715
- https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-44487