CVE-2023-44487
Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
In plain language
AI Act nowCVE-2023-44487 is an HTTP/2 bug that lets attackers overwhelm servers by rapidly cancelling many connection “streams,” and typical small businesses should treat it as urgent to fix if you run affected HTTP/2 software.
CVE-2023-44487 is a denial-of-service weakness in HTTP/2 implementations that allows an attacker to trigger rapid stream resets via request cancellation, consuming server resources; it requires no authentication and has been exploited in the wild (added to CISA KEV on 2023-10-10).
What to do now
- Check whether you run any of these products in your environment: simatic s7-1500 cpu 1518f-4 pn/dp mfp firmware, simatic s7-1500 cpu 1518-4 pn/dp mfp firmware, siplus s7-1500 cpu 1518-4 pn/dp mfp firmware, sinec ins, sinec nms, st7 scadaconnect, ruggedcom ape1808 firmware, http, nghttp2, netty.
- For each affected product, upgrade to the fixed version listed by the vendor (see step 4).
- If you cannot upgrade immediately, contact your vendor to confirm available mitigations or temporary defenses for “HTTP/2 rapid reset” style attacks.
- Apply the known fixed versions: sinec ins → 1.0; sinec nms → 3.0; st7 scadaconnect → 1.1; nghttp2 → 1.57.0; netty → 4.1.100; jetty → 9.4.53; caddy → 2.7.5; go → 1.20.10; http2 → 0.17.0; networking → 0.17.0; nginx plus → r29; swiftnio http/2 → 1.28.0.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-44487 and every CVE in our database. Create a free account — no credit card required.
Create Free Account