CVE-2023-44487

Published Oct 10, 2023

Last updated 8 days ago

Overview

Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
HTTP/2 Rapid Reset Attack Vulnerability
Exploit added on
Oct 10, 2023
Exploit action due
Oct 31, 2023
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-400

Social media

Hype score
Not currently trending
  1. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    12 Apr 2025

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2023-44487 CVE-2021-23017 CVE-2021-3618 141.95.17.178 port 22 | 80 | 9100 #Anonymous

    @saw11b

    12 Apr 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    12 Apr 2025

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    4 Apr 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    13 Mar 2025

    74 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. {"cpes":openbsd:openssh:8.4p1","cpe:/o:debian:debian_linux","cpe:/a:f5:nginx:1.18.0"],"hostnames":["https://t.co/KQeBMZwqHr",],"ip":"23.95.39.61","ports":[21,22,80,443,5222,5269],"tags":["eol-product"],"vulns":["CVE-2023-44487","CVE-2021-23017","CVE-2021-3618"]}

    @portknock

    10 Mar 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    8 Mar 2025

    185 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    22 Feb 2025

    138 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    5 Feb 2025

    193 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    4 Feb 2025

    182 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    24 Jan 2025

    155 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    15 Jan 2025

    54 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    31 Dec 2024

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2024-12698 An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were โ€ฆ https://t.co/VcOGtro9yB

    @CVEnew

    18 Dec 2024

    407 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    12 Dec 2024

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    2 Dec 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    26 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    22 Nov 2024

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. {"hostnames":["https://t.co/lsjL6hNT8q","https://t.co/Lurbv4tXGG"],"ip":"104.131.14.208","ports":[22,25,80,443,3000,3001],"tags":["cloud","self-signed","starttls","eol-product"],"vulns":["CVE-2021-23017","CVE-2021-3618","CVE-2023-44487"]}

    @ClumsyLulzReal

    17 Nov 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    1 Nov 2024

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    30 Oct 2024

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References