CVE-2023-44487
ietf http, Siemens RUGGEDCOM APE1808, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
Published 10 Oct 2023 · updated 11 Aug 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Oct 2023, with a remediation deadline of 31 Oct 2023 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
References
- www.openwall.com/lists/oss-security/2023/10/10/6 · Mailing List, Third Party Advisory
- www.openwall.com/lists/oss-security/2023/10/10/7 · Mailing List, Third Party Advisory
- www.openwall.com/lists/oss-security/2023/10/13/4 · Mailing List, Third Party Advisory
- www.openwall.com/lists/oss-security/2023/10/13/9 · Mailing List, Third Party Advisory
- www.openwall.com/lists/oss-security/2023/10/18/4 · Mailing List, Third Party Advisory
- www.openwall.com/lists/oss-security/2023/10/18/8 · Mailing List, Third Party Advisory
- www.openwall.com/lists/oss-security/2023/10/19/6 · Mailing List, Third Party Advisory
- www.openwall.com/lists/oss-security/2023/10/20/8 · Mailing List, Third Party Advisory
- access.redhat.com/security/cve/cve-2023-44487 · Vendor Advisory
- arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/ · Press/Media Coverage, Third Party Advisory
- aws.amazon.com/security/security-bulletins/AWS-2023-011/ · Third Party Advisory
- blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/ · Technical Description, Vendor Advisory
- blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/ · Third Party Advisory, Vendor Advisory
- blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/ · Vendor Advisory
- blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack · Press/Media Coverage, Third Party Advisory
- blog.vespa.ai/cve-2023-44487/ · Vendor Advisory
- bugzilla.proxmox.com/show_bug.cgi?id=4988 · Issue Tracking, Third Party Advisory
- bugzilla.redhat.com/show_bug.cgi?id=2242803 · Issue Tracking, Vendor Advisory
- bugzilla.suse.com/show_bug.cgi?id=1216123 · Issue Tracking, Vendor Advisory
- cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9 · Mailing List, Patch, Vendor Advisory
- cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/ · Technical Description, Vendor Advisory
- cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack · Technical Description, Vendor Advisory
- community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125 · Vendor Advisory
- discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715 · Third Party Advisory
- edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve · Broken Link