CVE Tools

Description

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

In plain language

AI Act now

CVE-2023-44487 is an HTTP/2 bug that lets attackers overwhelm servers by rapidly cancelling many connection “streams,” and typical small businesses should treat it as urgent to fix if you run affected HTTP/2 software.

Executive summary

CVE-2023-44487 is a denial-of-service weakness in HTTP/2 implementations that allows an attacker to trigger rapid stream resets via request cancellation, consuming server resources; it requires no authentication and has been exploited in the wild (added to CISA KEV on 2023-10-10).

If affected, business impact
Service outage for your applicationsWeb/API performance collapseBusiness disruption during attacksHigher hosting/network costs

What to do now

  1. Check whether you run any of these products in your environment: simatic s7-1500 cpu 1518f-4 pn/dp mfp firmware, simatic s7-1500 cpu 1518-4 pn/dp mfp firmware, siplus s7-1500 cpu 1518-4 pn/dp mfp firmware, sinec ins, sinec nms, st7 scadaconnect, ruggedcom ape1808 firmware, http, nghttp2, netty.
  2. For each affected product, upgrade to the fixed version listed by the vendor (see step 4).
  3. If you cannot upgrade immediately, contact your vendor to confirm available mitigations or temporary defenses for “HTTP/2 rapid reset” style attacks.
  4. Apply the known fixed versions: sinec ins → 1.0; sinec nms → 3.0; st7 scadaconnect → 1.1; nghttp2 → 1.57.0; netty → 4.1.100; jetty → 9.4.53; caddy → 2.7.5; go → 1.20.10; http2 → 0.17.0; networking → 0.17.0; nginx plus → r29; swiftnio http/2 → 1.28.0.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:NI:NA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:NConfidentiality
None
I:NIntegrity
None
A:HAvailability
High

Weaknesses

Affected Products

and 206 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Oct 10, 2023
Remediation due:Oct 31, 2023

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

2 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available
Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Impact
View detailed technique mapping

References

and 540 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2023-44487 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows