SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9512

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service.

HIGH 7.5EPSS 83.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 83.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
83.43% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
apple/swiftnio · apache/traffic server · debian/debian linux · nodejs/node.js
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.