CVE-2023-44487

Published Oct 10, 2023

Last updated 2 months ago

Overview

Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
HTTP/2 Rapid Reset Attack Vulnerability
Exploit added on
Oct 10, 2023
Exploit action due
Oct 31, 2023
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-400

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    22 Feb 2025

    138 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    5 Feb 2025

    193 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    4 Feb 2025

    182 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    24 Jan 2025

    155 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    15 Jan 2025

    54 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    31 Dec 2024

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-12698 An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were โ€ฆ https://t.co/VcOGtro9yB

    @CVEnew

    18 Dec 2024

    407 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    12 Dec 2024

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/FFRPGsHxyT

    @xer0dayz

    2 Dec 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    26 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    22 Nov 2024

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. {"hostnames":["https://t.co/lsjL6hNT8q","https://t.co/Lurbv4tXGG"],"ip":"104.131.14.208","ports":[22,25,80,443,3000,3001],"tags":["cloud","self-signed","starttls","eol-product"],"vulns":["CVE-2021-23017","CVE-2021-3618","CVE-2023-44487"]}

    @ClumsyLulzReal

    17 Nov 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    1 Nov 2024

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. ๐Ÿ”’ Our latest Fuzzer module update enhances web security testing with dynamic search for URL file lists, Nuclei's custom scan options, basic authentication brute force, CVE-2023-44487 HTTP2 DDoS testing, and HTTP Smuggler for single and multi-targets. ๐Ÿ’ป๐Ÿ” https://t.co/slTk10eGH8

    @Sn1perSecurity

    30 Oct 2024

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References