SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9515

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service.

HIGH 7.5EPSS 87.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 87.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
87.40% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-400, CWE-770
Affected
apple/swiftnio · apache/traffic server · canonical/ubuntu linux · debian/debian linux · synology/skynas · synology/diskstation manager · synology/vs960hd firmware · fedoraproject/fedora · opensuse/leap · redhat/jboss core services · redhat/jboss enterprise application platform · redhat/openshift container platform · redhat/openshift service mesh · redhat/openstack · redhat/quay · redhat/single sign-on · redhat/software collections · redhat/enterprise linux · oracle/graalvm · mcafee/web gateway · +2 more
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.