CVE-2023-44487
HTTP/2 Rapid Reset Attack Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 31 October 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Listed 10 October 2023 · due 31 October 2023
- Weakness
- CWE-400
- Affected
- siemens/simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · siemens/sinec ins · siemens/sinec nms · siemens/st7 scadaconnect · siemens/ruggedcom ape1808 firmware · siemens/simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware · siemens/siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware · ietf/http · nghttp2/nghttp2 · netty/netty · envoyproxy/envoy · eclipse/jetty · caddyserver/caddy · golang/go · golang/http2 · golang/networking · f5/big-ip access policy manager · f5/big-ip advanced firewall manager · f5/big-ip advanced web application firewall · f5/big-ip analytics · +40 more
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/; https://nvd.nist.gov/vuln/detail/CVE-2023-44487
References
- http://www.openwall.com/lists/oss-security/2023/10/10/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/10/7Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/13/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/13/9Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/18/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/18/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/19/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/20/8Mailing List, Third Party Advisory
- https://access.redhat.com/security/cve/cve-2023-44487Vendor Advisory
- https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/Press/Media Coverage, Third Party Advisory
- https://aws.amazon.com/security/security-bulletins/AWS-2023-011/Third Party Advisory
- https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/Technical Description, Vendor Advisory
- https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/Third Party Advisory, Vendor Advisory
- https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/Vendor Advisory
- https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attackPress/Media Coverage, Third Party Advisory
- https://blog.vespa.ai/cve-2023-44487/Vendor Advisory
- https://bugzilla.proxmox.com/show_bug.cgi?id=4988Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803Issue Tracking, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1216123Issue Tracking, Vendor Advisory
- https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9Mailing List, Patch, Vendor Advisory
- https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/Technical Description, Vendor Advisory
- https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attackTechnical Description, Vendor Advisory
- https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125Vendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715Third Party Advisory
- https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cveBroken Link
- https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764Vendor Advisory
- https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088Issue Tracking, Patch
- https://github.com/Azure/AKS/issues/3947Issue Tracking
- https://github.com/Kong/kong/discussions/11741Issue Tracking
- https://github.com/advisories/GHSA-qppj-fm5r-hxr3Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.