7.5

CVE-2023-44487

Warnung
Medienbericht
Exploit

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IetfHttp Version2.0
Nghttp2Nghttp2 Version < 1.57.0
NettyNetty Version < 4.1.100
EnvoyproxyEnvoy Version1.24.10
EnvoyproxyEnvoy Version1.25.9
EnvoyproxyEnvoy Version1.26.4
EnvoyproxyEnvoy Version1.27.0
EclipseJetty Version < 9.4.53
EclipseJetty Version >= 10.0.0 < 10.0.17
EclipseJetty Version >= 11.0.0 < 11.0.17
EclipseJetty Version >= 12.0.0 < 12.0.2
CaddyserverCaddy Version < 2.7.5
GolangGo Version < 1.20.10
GolangGo Version >= 1.21.0 < 1.21.3
GolangHttp2 SwPlatformgo Version < 0.17.0
GolangNetworking SwPlatformgo Version < 0.17.0
F5Big-ip Access Policy Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Access Policy Manager Version >= 14.1.0 <= 14.1.5
F5Big-ip Access Policy Manager Version >= 15.1.0 <= 15.1.10
F5Big-ip Access Policy Manager Version >= 16.1.0 <= 16.1.4
F5Big-ip Access Policy Manager Version17.1.0
F5Big-ip Advanced Firewall Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Advanced Firewall Manager Version >= 14.1.0 <= 14.1.5
F5Big-ip Advanced Firewall Manager Version >= 15.1.0 <= 15.1.10
F5Big-ip Advanced Firewall Manager Version >= 16.1.0 <= 16.1.4
F5Big-ip Advanced Web Application Firewall Version >= 13.1.0 <= 13.1.5
F5Big-ip Advanced Web Application Firewall Version >= 14.1.0 <= 14.1.5
F5Big-ip Advanced Web Application Firewall Version >= 15.1.0 <= 15.1.10
F5Big-ip Advanced Web Application Firewall Version >= 16.1.0 <= 16.1.4
F5Big-ip Analytics Version >= 13.1.0 <= 13.1.5
F5Big-ip Analytics Version >= 14.1.0 <= 14.1.5
F5Big-ip Analytics Version >= 15.1.0 <= 15.1.10
F5Big-ip Analytics Version >= 16.1.0 <= 16.1.4
F5Big-ip Analytics Version17.1.0
F5Big-ip Application Acceleration Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Application Acceleration Manager Version >= 14.1.0 <= 14.1.5
F5Big-ip Application Acceleration Manager Version >= 15.1.0 <= 15.1.10
F5Big-ip Application Acceleration Manager Version >= 16.1.0 <= 16.1.4
F5Big-ip Application Security Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Application Security Manager Version >= 14.1.0 <= 14.1.5
F5Big-ip Application Security Manager Version >= 15.1.0 <= 15.1.10
F5Big-ip Application Security Manager Version >= 16.1.0 <= 16.1.4
F5Big-ip Application Visibility And Reporting Version >= 13.1.0 <= 13.1.5
F5Big-ip Application Visibility And Reporting Version >= 14.1.0 <= 14.1.5
F5Big-ip Application Visibility And Reporting Version >= 15.1.0 <= 15.1.10
F5Big-ip Application Visibility And Reporting Version >= 16.1.0 <= 16.1.4
F5Big-ip Carrier-grade Nat Version >= 13.1.0 <= 13.1.5
F5Big-ip Carrier-grade Nat Version >= 14.1.0 <= 14.1.5
F5Big-ip Carrier-grade Nat Version >= 15.1.0 <= 15.1.10
F5Big-ip Carrier-grade Nat Version >= 16.1.0 <= 16.1.4
F5Big-ip Carrier-grade Nat Version17.1.0
F5Big-ip Ddos Hybrid Defender Version >= 13.1.0 <= 13.1.5
F5Big-ip Ddos Hybrid Defender Version >= 14.1.0 <= 14.1.5
F5Big-ip Ddos Hybrid Defender Version >= 15.1.0 <= 15.1.10
F5Big-ip Ddos Hybrid Defender Version >= 16.1.0 <= 16.1.4
F5Big-ip Ddos Hybrid Defender Version17.1.0
F5Big-ip Domain Name System Version >= 13.1.0 <= 13.1.5
F5Big-ip Domain Name System Version >= 14.1.0 <= 14.1.5
F5Big-ip Domain Name System Version >= 15.1.0 <= 15.1.10
F5Big-ip Domain Name System Version >= 16.1.0 <= 16.1.4
F5Big-ip Domain Name System Version17.1.0
F5Big-ip Fraud Protection Service Version >= 13.1.0 <= 13.1.5
F5Big-ip Fraud Protection Service Version >= 14.1.0 <= 14.1.5
F5Big-ip Fraud Protection Service Version >= 15.1.0 <= 15.1.10
F5Big-ip Fraud Protection Service Version >= 16.1.0 <= 16.1.4
F5Big-ip Global Traffic Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Global Traffic Manager Version >= 14.1.0 <= 14.1.5
F5Big-ip Global Traffic Manager Version >= 15.1.0 <= 15.1.10
F5Big-ip Global Traffic Manager Version >= 16.1.0 <= 16.1.4
F5Big-ip Global Traffic Manager Version17.1.0
F5Big-ip Link Controller Version >= 13.1.0 <= 13.1.5
F5Big-ip Link Controller Version >= 14.1.0 <= 14.1.5
F5Big-ip Link Controller Version >= 15.1.0 <= 15.1.10
F5Big-ip Link Controller Version >= 16.1.0 <= 16.1.4
F5Big-ip Link Controller Version17.1.0
F5Big-ip Local Traffic Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Local Traffic Manager Version >= 14.1.0 <= 14.1.5
F5Big-ip Local Traffic Manager Version >= 15.1.0 <= 15.1.10
F5Big-ip Local Traffic Manager Version >= 16.1.0 <= 16.1.4
F5Big-ip Local Traffic Manager Version17.1.0
F5Big-ip Next Version20.0.1
F5Big-ip Next Service Proxy For Kubernetes Version >= 1.5.0 <= 1.8.2
F5Big-ip Policy Enforcement Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Policy Enforcement Manager Version >= 14.1.0 <= 14.1.5
F5Big-ip Policy Enforcement Manager Version >= 15.1.0 <= 15.1.10
F5Big-ip Policy Enforcement Manager Version >= 16.1.0 <= 16.1.4
F5Big-ip Ssl Orchestrator Version >= 13.1.0 <= 13.1.5
F5Big-ip Ssl Orchestrator Version >= 14.1.0 <= 14.1.5
F5Big-ip Ssl Orchestrator Version >= 15.1.0 <= 15.1.10
F5Big-ip Ssl Orchestrator Version >= 16.1.0 <= 16.1.4
F5Big-ip Ssl Orchestrator Version17.1.0
F5Big-ip Webaccelerator Version >= 13.1.0 <= 13.1.5
F5Big-ip Webaccelerator Version >= 14.1.0 <= 14.1.5
F5Big-ip Webaccelerator Version >= 15.1.0 <= 15.1.10
F5Big-ip Webaccelerator Version >= 16.1.0 <= 16.1.4
F5Big-ip Webaccelerator Version17.1.0
F5Big-ip Websafe Version >= 13.1.0 <= 13.1.5
F5Big-ip Websafe Version >= 14.1.0 <= 14.1.5
F5Big-ip Websafe Version >= 15.1.0 <= 15.1.10
F5Big-ip Websafe Version >= 16.1.0 <= 16.1.4
F5Big-ip Websafe Version17.1.0
F5Nginx Version >= 1.9.5 <= 1.25.2
F5Nginx Ingress Controller Version >= 2.0.0 <= 2.4.2
F5Nginx Ingress Controller Version >= 3.0.0 <= 3.3.0
F5Nginx Plus Version >= r25 < r29
F5Nginx Plus Versionr29 Update-
F5Nginx Plus Versionr30 Update-
ApacheTomcat Version >= 8.5.0 <= 8.5.93
ApacheTomcat Version >= 9.0.0 <= 9.0.80
ApacheTomcat Version >= 10.1.0 <= 10.1.13
ApacheTomcat Version11.0.0 Updatemilestone1
ApacheTomcat Version11.0.0 Updatemilestone10
ApacheTomcat Version11.0.0 Updatemilestone11
ApacheTomcat Version11.0.0 Updatemilestone2
ApacheTomcat Version11.0.0 Updatemilestone3
ApacheTomcat Version11.0.0 Updatemilestone4
ApacheTomcat Version11.0.0 Updatemilestone5
ApacheTomcat Version11.0.0 Updatemilestone6
ApacheTomcat Version11.0.0 Updatemilestone7
ApacheTomcat Version11.0.0 Updatemilestone8
ApacheTomcat Version11.0.0 Updatemilestone9
GrpcGrpc SwPlatformgo Version < 1.56.3
GrpcGrpc SwPlatform- Version <= 1.59.2
GrpcGrpc SwPlatformgo Version >= 1.58.0 < 1.58.3
GrpcGrpc Version1.57.0 Update- SwPlatformgo
Microsoft.Net Version >= 6.0.0 < 6.0.23
Microsoft.Net Version >= 7.0.0 < 7.0.12
MicrosoftAsp.Net Core Version >= 6.0.0 < 6.0.23
MicrosoftAsp.Net Core Version >= 7.0.0 < 7.0.12
MicrosoftAzure Kubernetes Service Version < 2023-10-08
MicrosoftVisual Studio 2022 Version >= 17.0 < 17.2.20
MicrosoftVisual Studio 2022 Version >= 17.4 < 17.4.12
MicrosoftVisual Studio 2022 Version >= 17.6 < 17.6.8
MicrosoftVisual Studio 2022 Version >= 17.7 < 17.7.5
MicrosoftWindows 10 1607 HwPlatformx64 Version < 10.0.14393.6351
MicrosoftWindows 10 1607 HwPlatformx86 Version < 10.0.14393.6351
MicrosoftWindows 10 1809 Version < 10.0.17763.4974
MicrosoftWindows 10 21h2 Version < 10.0.19044.3570
MicrosoftWindows 10 22h2 Version < 10.0.19045.3570
MicrosoftWindows 11 21h2 Version < 10.0.22000.2538
MicrosoftWindows 11 22h2 Version < 10.0.22621.2428
NodejsNode.Js Version >= 18.0.0 < 18.18.2
NodejsNode.Js Version >= 20.0.0 < 20.8.1
MicrosoftCbl-mariner Version < 2023-10-11
DenaH2o Version < 2023-10-10
FacebookProxygen Version < 2023.10.16.00
ApacheApisix Version < 3.6.1
ApacheTraffic Server Version >= 8.0.0 < 8.1.9
ApacheTraffic Server Version >= 9.0.0 < 9.2.3
AmazonOpensearch Data Prepper Version < 2.5.0
DebianDebian Linux Version10.0
DebianDebian Linux Version11.0
DebianDebian Linux Version12.0
Kazu-yamamotoHttp2 Version < 4.2.2
IstioIstio Version < 1.17.6
IstioIstio Version >= 1.18.0 < 1.18.3
IstioIstio Version >= 1.19.0 < 1.19.1
Varnish Cache ProjectVarnish Cache Version < 2023-10-10
TraefikTraefik Version < 2.10.5
TraefikTraefik Version3.0.0 Updatebeta1
TraefikTraefik Version3.0.0 Updatebeta2
TraefikTraefik Version3.0.0 Updatebeta3
ProjectcontourContour SwPlatformkubernetes Version < 2023-10-11
LinkerdLinkerd SwEditionstable SwPlatformkubernetes Version >= 2.12.0 <= 2.12.5
LinkerdLinkerd Version2.13.0 SwEditionstable SwPlatformkubernetes
LinkerdLinkerd Version2.13.1 SwEditionstable SwPlatformkubernetes
LinkerdLinkerd Version2.14.0 SwEditionstable SwPlatformkubernetes
LinkerdLinkerd Version2.14.1 SwEditionstable SwPlatformkubernetes
LinecorpArmeria Version < 1.26.0
RedhatBuild Of Optaplanner Version8.0
RedhatBuild Of Quarkus Version-
RedhatCeph Storage Version5.0
RedhatCost Management Version-
RedhatCryostat Version2.0
RedhatDecision Manager Version7.0
RedhatJboss A-mq Version7
RedhatJboss A-mq Streams Version-
RedhatJboss Data Grid Version7.0.0
RedhatJboss Fuse Version6.0.0
RedhatJboss Fuse Version7.0.0
RedhatOpenshift Version- SwPlatformaws
RedhatOpenshift Gitops Version-
RedhatOpenstack Platform Version16.1
RedhatOpenstack Platform Version16.2
RedhatOpenstack Platform Version17.1
RedhatProcess Automation Version7.0
RedhatQuay Version3.0.0
RedhatSatellite Version6.0
RedhatService Interconnect Version1.0
RedhatSingle Sign-on Version7.0
RedhatWeb Terminal Version-
RedhatEnterprise Linux Version6.0
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Version9.0
RedhatService Telemetry Framework Version1.5
   RedhatEnterprise Linux Version8.0
FedoraprojectFedora Version37
FedoraprojectFedora Version38
NetappOncommand Insight Version-
AkkaHttp Server Version < 10.5.3
KonghqKong Gateway SwEditionenterprise Version < 3.4.2
JenkinsJenkins SwEditionlts Version <= 2.414.2
JenkinsJenkins SwEdition- Version <= 2.427
ApacheSolr Version < 9.4.0
OpenrestyOpenresty Version < 1.21.4.3
CiscoBusiness Process Automation Version < 3.2.003.009
CiscoCrosswork Data Gateway Version < 4.1.3
CiscoCrosswork Data Gateway Version >= 5.0.0 < 5.0.2
CiscoExpressway Version < x14.3.3
CiscoFirepower Threat Defense Version < 7.4.2
CiscoIot Field Network Director Version < 4.11.0
CiscoPrime Access Registrar Version < 9.3.3
CiscoPrime Cable Provisioning Version < 7.2.1
CiscoPrime Infrastructure Version < 3.10.4
CiscoPrime Network Registrar Version < 11.2
CiscoSecure Malware Analytics Version < 2.19.2
CiscoFog Director Version < 1.22
CiscoIos Xe Version < 17.15.1
CiscoIos Xr Version < 7.11.2
CiscoSecure Web Appliance Firmware Version < 15.1.0
   CiscoSecure Web Appliance Version-
CiscoNx-os Version < 10.2\(7\)
   CiscoNexus 3016 Version-
   CiscoNexus 3016q Version-
   CiscoNexus 3048 Version-
   CiscoNexus 3064 Version-
   CiscoNexus 3064-32t Version-
   CiscoNexus 3064-t Version-
   CiscoNexus 3064-x Version-
   CiscoNexus 3064t Version-
   CiscoNexus 3064x Version-
   CiscoNexus 3100 Version-
   CiscoNexus 3100-v Version-
   CiscoNexus 3100-z Version-
   CiscoNexus 3100v Version-
   CiscoNexus 31108pc-v Version-
   CiscoNexus 31108pv-v Version-
   CiscoNexus 31108tc-v Version-
   CiscoNexus 31128pq Version-
   CiscoNexus 3132c-z Version-
   CiscoNexus 3132q Version-
   CiscoNexus 3132q-v Version-
   CiscoNexus 3132q-x Version-
   CiscoNexus 3132q-xl Version-
   CiscoNexus 3164q Version-
   CiscoNexus 3172 Version-
   CiscoNexus 3172pq Version-
   CiscoNexus 3172pq-xl Version-
   CiscoNexus 3172tq Version-
   CiscoNexus 3172tq-32t Version-
   CiscoNexus 3172tq-xl Version-
   CiscoNexus 3200 Version-
   CiscoNexus 3232 Version-
   CiscoNexus 3232c Version-
   CiscoNexus 3232c Version-
   CiscoNexus 3264c-e Version-
   CiscoNexus 3264q Version-
   CiscoNexus 3400 Version-
   CiscoNexus 3408-s Version-
   CiscoNexus 34180yc Version-
   CiscoNexus 34200yc-sm Version-
   CiscoNexus 3432d-s Version-
   CiscoNexus 3464c Version-
   CiscoNexus 3500 Version-
   CiscoNexus 3524 Version-
   CiscoNexus 3524-x Version-
   CiscoNexus 3524-xl Version-
   CiscoNexus 3548 Version-
   CiscoNexus 3548-x Version-
   CiscoNexus 3548-xl Version-
   CiscoNexus 3600 Version-
   CiscoNexus 36180yc-r Version-
   CiscoNexus 3636c-r Version-
CiscoNx-os Version >= 10.3\(1\) < 10.3\(5\)
   CiscoNexus 3016 Version-
   CiscoNexus 3016q Version-
   CiscoNexus 3048 Version-
   CiscoNexus 3064 Version-
   CiscoNexus 3064-32t Version-
   CiscoNexus 3064-t Version-
   CiscoNexus 3064-x Version-
   CiscoNexus 3064t Version-
   CiscoNexus 3064x Version-
   CiscoNexus 3100 Version-
   CiscoNexus 3100-v Version-
   CiscoNexus 3100-z Version-
   CiscoNexus 3100v Version-
   CiscoNexus 31108pc-v Version-
   CiscoNexus 31108pv-v Version-
   CiscoNexus 31108tc-v Version-
   CiscoNexus 31128pq Version-
   CiscoNexus 3132c-z Version-
   CiscoNexus 3132q Version-
   CiscoNexus 3132q-v Version-
   CiscoNexus 3132q-x Version-
   CiscoNexus 3132q-xl Version-
   CiscoNexus 3164q Version-
   CiscoNexus 3172 Version-
   CiscoNexus 3172pq Version-
   CiscoNexus 3172pq-xl Version-
   CiscoNexus 3172tq Version-
   CiscoNexus 3172tq-32t Version-
   CiscoNexus 3172tq-xl Version-
   CiscoNexus 3200 Version-
   CiscoNexus 3232 Version-
   CiscoNexus 3232c Version-
   CiscoNexus 3232c Version-
   CiscoNexus 3264c-e Version-
   CiscoNexus 3264q Version-
   CiscoNexus 3400 Version-
   CiscoNexus 3408-s Version-
   CiscoNexus 34180yc Version-
   CiscoNexus 34200yc-sm Version-
   CiscoNexus 3432d-s Version-
   CiscoNexus 3464c Version-
   CiscoNexus 3500 Version-
   CiscoNexus 3524 Version-
   CiscoNexus 3524-x Version-
   CiscoNexus 3524-xl Version-
   CiscoNexus 3548 Version-
   CiscoNexus 3548-x Version-
   CiscoNexus 3548-xl Version-
   CiscoNexus 3600 Version-
   CiscoNexus 36180yc-r Version-
   CiscoNexus 3636c-r Version-
CiscoNx-os Version >= 10.4\(1\) < 10.4\(2\)
   CiscoNexus 3016 Version-
   CiscoNexus 3016q Version-
   CiscoNexus 3048 Version-
   CiscoNexus 3064 Version-
   CiscoNexus 3064-32t Version-
   CiscoNexus 3064-t Version-
   CiscoNexus 3064-x Version-
   CiscoNexus 3064t Version-
   CiscoNexus 3064x Version-
   CiscoNexus 3100 Version-
   CiscoNexus 3100-v Version-
   CiscoNexus 3100-z Version-
   CiscoNexus 3100v Version-
   CiscoNexus 31108pc-v Version-
   CiscoNexus 31108pv-v Version-
   CiscoNexus 31108tc-v Version-
   CiscoNexus 31128pq Version-
   CiscoNexus 3132c-z Version-
   CiscoNexus 3132q Version-
   CiscoNexus 3132q-v Version-
   CiscoNexus 3132q-x Version-
   CiscoNexus 3132q-xl Version-
   CiscoNexus 3164q Version-
   CiscoNexus 3172 Version-
   CiscoNexus 3172pq Version-
   CiscoNexus 3172pq-xl Version-
   CiscoNexus 3172tq Version-
   CiscoNexus 3172tq-32t Version-
   CiscoNexus 3172tq-xl Version-
   CiscoNexus 3200 Version-
   CiscoNexus 3232 Version-
   CiscoNexus 3232c Version-
   CiscoNexus 3232c Version-
   CiscoNexus 3264c-e Version-
   CiscoNexus 3264q Version-
   CiscoNexus 3400 Version-
   CiscoNexus 3408-s Version-
   CiscoNexus 34180yc Version-
   CiscoNexus 34200yc-sm Version-
   CiscoNexus 3432d-s Version-
   CiscoNexus 3464c Version-
   CiscoNexus 3500 Version-
   CiscoNexus 3524 Version-
   CiscoNexus 3524-x Version-
   CiscoNexus 3524-xl Version-
   CiscoNexus 3548 Version-
   CiscoNexus 3548-x Version-
   CiscoNexus 3548-xl Version-
   CiscoNexus 3600 Version-
   CiscoNexus 36180yc-r Version-
   CiscoNexus 3636c-r Version-
CiscoNx-os Version < 10.2\(7\)
   CiscoNexus 9000v Version-
   CiscoNexus 9200 Version-
   CiscoNexus 9200yc Version-
   CiscoNexus 92160yc-x Version-
   CiscoNexus 92160yc Switch Version-
   CiscoNexus 9221c Version-
   CiscoNexus 92300yc Version-
   CiscoNexus 92300yc Switch Version-
   CiscoNexus 92304qc Version-
   CiscoNexus 92304qc Switch Version-
   CiscoNexus 9232e Version-
   CiscoNexus 92348gc-x Version-
   CiscoNexus 9236c Version-
   CiscoNexus 9236c Switch Version-
   CiscoNexus 9272q Version-
   CiscoNexus 9272q Switch Version-
   CiscoNexus 9300 Version-
   CiscoNexus 93108tc-ex Version-
   CiscoNexus 93108tc-ex-24 Version-
   CiscoNexus 93108tc-ex Switch Version-
   CiscoNexus 93108tc-fx Version-
   CiscoNexus 93108tc-fx-24 Version-
   CiscoNexus 93108tc-fx3h Version-
   CiscoNexus 93108tc-fx3p Version-
   CiscoNexus 93120tx Version-
   CiscoNexus 93120tx Switch Version-
   CiscoNexus 93128 Version-
   CiscoNexus 93128tx Version-
   CiscoNexus 93128tx Switch Version-
   CiscoNexus 9316d-gx Version-
   CiscoNexus 93180lc-ex Version-
   CiscoNexus 93180lc-ex Switch Version-
   CiscoNexus 93180tc-ex Version-
   CiscoNexus 93180yc-ex Version-
   CiscoNexus 93180yc-ex-24 Version-
   CiscoNexus 93180yc-ex Switch Version-
   CiscoNexus 93180yc-fx Version-
   CiscoNexus 93180yc-fx-24 Version-
   CiscoNexus 93180yc-fx3 Version-
   CiscoNexus 93180yc-fx3h Version-
   CiscoNexus 93180yc-fx3s Version-
   CiscoNexus 93216tc-fx2 Version-
   CiscoNexus 93240tc-fx2 Version-
   CiscoNexus 93240yc-fx2 Version-
   CiscoNexus 9332c Version-
   CiscoNexus 9332d-gx2b Version-
   CiscoNexus 9332d-h2r Version-
   CiscoNexus 9332pq Version-
   CiscoNexus 9332pq Switch Version-
   CiscoNexus 93360yc-fx2 Version-
   CiscoNexus 9336c-fx2 Version-
   CiscoNexus 9336c-fx2-e Version-
   CiscoNexus 9336pq Version-
   CiscoNexus 9336pq Aci Version-
   CiscoNexus 9336pq Aci Spine Version-
   CiscoNexus 9336pq Aci Spine Switch Version-
   CiscoNexus 9348d-gx2a Version-
   CiscoNexus 9348gc-fx3 Version-
   CiscoNexus 9348gc-fxp Version-
   CiscoNexus 93600cd-gx Version-
   CiscoNexus 9364c Version-
   CiscoNexus 9364c-gx Version-
   CiscoNexus 9364d-gx2a Version-
   CiscoNexus 9372px Version-
   CiscoNexus 9372px-e Version-
   CiscoNexus 9372px-e Switch Version-
   CiscoNexus 9372px Switch Version-
   CiscoNexus 9372tx Version-
   CiscoNexus 9372tx-e Version-
   CiscoNexus 9372tx-e Switch Version-
   CiscoNexus 9372tx Switch Version-
   CiscoNexus 9396px Version-
   CiscoNexus 9396px Switch Version-
   CiscoNexus 9396tx Version-
   CiscoNexus 9396tx Switch Version-
   CiscoNexus 9408 Version-
   CiscoNexus 9432pq Version-
   CiscoNexus 9500 Version-
   CiscoNexus 9500 16-slot Version-
   CiscoNexus 9500 4-slot Version-
   CiscoNexus 9500 8-slot Version-
   CiscoNexus 9500 Supervisor A Version-
   CiscoNexus 9500 Supervisor B Version-
   CiscoNexus 9500r Version-
   CiscoNexus 9504 Version-
   CiscoNexus 9504 Switch Version-
   CiscoNexus 9508 Version-
   CiscoNexus 9508 Switch Version-
   CiscoNexus 9516 Version-
   CiscoNexus 9516 Switch Version-
   CiscoNexus 9536pq Version-
   CiscoNexus 9636pq Version-
   CiscoNexus 9716d-gx Version-
   CiscoNexus 9736pq Version-
   CiscoNexus 9800 Version-
   CiscoNexus 9804 Version-
   CiscoNexus 9808 Version-
CiscoNx-os Version >= 10.3\(1\) < 10.3\(5\)
   CiscoNexus 9000v Version-
   CiscoNexus 9200 Version-
   CiscoNexus 9200yc Version-
   CiscoNexus 92160yc-x Version-
   CiscoNexus 92160yc Switch Version-
   CiscoNexus 9221c Version-
   CiscoNexus 92300yc Version-
   CiscoNexus 92300yc Switch Version-
   CiscoNexus 92304qc Version-
   CiscoNexus 92304qc Switch Version-
   CiscoNexus 9232e Version-
   CiscoNexus 92348gc-x Version-
   CiscoNexus 9236c Version-
   CiscoNexus 9236c Switch Version-
   CiscoNexus 9272q Version-
   CiscoNexus 9272q Switch Version-
   CiscoNexus 9300 Version-
   CiscoNexus 93108tc-ex Version-
   CiscoNexus 93108tc-ex-24 Version-
   CiscoNexus 93108tc-ex Switch Version-
   CiscoNexus 93108tc-fx Version-
   CiscoNexus 93108tc-fx-24 Version-
   CiscoNexus 93108tc-fx3h Version-
   CiscoNexus 93108tc-fx3p Version-
   CiscoNexus 93120tx Version-
   CiscoNexus 93120tx Switch Version-
   CiscoNexus 93128 Version-
   CiscoNexus 93128tx Version-
   CiscoNexus 93128tx Switch Version-
   CiscoNexus 9316d-gx Version-
   CiscoNexus 93180lc-ex Version-
   CiscoNexus 93180lc-ex Switch Version-
   CiscoNexus 93180tc-ex Version-
   CiscoNexus 93180yc-ex Version-
   CiscoNexus 93180yc-ex-24 Version-
   CiscoNexus 93180yc-ex Switch Version-
   CiscoNexus 93180yc-fx Version-
   CiscoNexus 93180yc-fx-24 Version-
   CiscoNexus 93180yc-fx3 Version-
   CiscoNexus 93180yc-fx3h Version-
   CiscoNexus 93180yc-fx3s Version-
   CiscoNexus 93216tc-fx2 Version-
   CiscoNexus 93240tc-fx2 Version-
   CiscoNexus 93240yc-fx2 Version-
   CiscoNexus 9332c Version-
   CiscoNexus 9332d-gx2b Version-
   CiscoNexus 9332d-h2r Version-
   CiscoNexus 9332pq Version-
   CiscoNexus 9332pq Switch Version-
   CiscoNexus 93360yc-fx2 Version-
   CiscoNexus 9336c-fx2 Version-
   CiscoNexus 9336c-fx2-e Version-
   CiscoNexus 9336pq Version-
   CiscoNexus 9336pq Aci Version-
   CiscoNexus 9336pq Aci Spine Version-
   CiscoNexus 9336pq Aci Spine Switch Version-
   CiscoNexus 9348d-gx2a Version-
   CiscoNexus 9348gc-fx3 Version-
   CiscoNexus 9348gc-fxp Version-
   CiscoNexus 93600cd-gx Version-
   CiscoNexus 9364c Version-
   CiscoNexus 9364c-gx Version-
   CiscoNexus 9364d-gx2a Version-
   CiscoNexus 9372px Version-
   CiscoNexus 9372px-e Version-
   CiscoNexus 9372px-e Switch Version-
   CiscoNexus 9372px Switch Version-
   CiscoNexus 9372tx Version-
   CiscoNexus 9372tx-e Version-
   CiscoNexus 9372tx-e Switch Version-
   CiscoNexus 9372tx Switch Version-
   CiscoNexus 9396px Version-
   CiscoNexus 9396px Switch Version-
   CiscoNexus 9396tx Version-
   CiscoNexus 9396tx Switch Version-
   CiscoNexus 9408 Version-
   CiscoNexus 9432pq Version-
   CiscoNexus 9500 Version-
   CiscoNexus 9500 16-slot Version-
   CiscoNexus 9500 4-slot Version-
   CiscoNexus 9500 8-slot Version-
   CiscoNexus 9500 Supervisor A Version-
   CiscoNexus 9500 Supervisor B Version-
   CiscoNexus 9500r Version-
   CiscoNexus 9504 Version-
   CiscoNexus 9504 Switch Version-
   CiscoNexus 9508 Version-
   CiscoNexus 9508 Switch Version-
   CiscoNexus 9516 Version-
   CiscoNexus 9516 Switch Version-
   CiscoNexus 9536pq Version-
   CiscoNexus 9636pq Version-
   CiscoNexus 9716d-gx Version-
   CiscoNexus 9736pq Version-
   CiscoNexus 9800 Version-
   CiscoNexus 9804 Version-
   CiscoNexus 9808 Version-
CiscoNx-os Version >= 10.4\(1\) < 10.4\(2\)
   CiscoNexus 9000v Version-
   CiscoNexus 9200 Version-
   CiscoNexus 9200yc Version-
   CiscoNexus 92160yc-x Version-
   CiscoNexus 92160yc Switch Version-
   CiscoNexus 9221c Version-
   CiscoNexus 92300yc Version-
   CiscoNexus 92300yc Switch Version-
   CiscoNexus 92304qc Version-
   CiscoNexus 92304qc Switch Version-
   CiscoNexus 9232e Version-
   CiscoNexus 92348gc-x Version-
   CiscoNexus 9236c Version-
   CiscoNexus 9236c Switch Version-
   CiscoNexus 9272q Version-
   CiscoNexus 9272q Switch Version-
   CiscoNexus 9300 Version-
   CiscoNexus 93108tc-ex Version-
   CiscoNexus 93108tc-ex-24 Version-
   CiscoNexus 93108tc-ex Switch Version-
   CiscoNexus 93108tc-fx Version-
   CiscoNexus 93108tc-fx-24 Version-
   CiscoNexus 93108tc-fx3h Version-
   CiscoNexus 93108tc-fx3p Version-
   CiscoNexus 93120tx Version-
   CiscoNexus 93120tx Switch Version-
   CiscoNexus 93128 Version-
   CiscoNexus 93128tx Version-
   CiscoNexus 93128tx Switch Version-
   CiscoNexus 9316d-gx Version-
   CiscoNexus 93180lc-ex Version-
   CiscoNexus 93180lc-ex Switch Version-
   CiscoNexus 93180tc-ex Version-
   CiscoNexus 93180yc-ex Version-
   CiscoNexus 93180yc-ex-24 Version-
   CiscoNexus 93180yc-ex Switch Version-
   CiscoNexus 93180yc-fx Version-
   CiscoNexus 93180yc-fx-24 Version-
   CiscoNexus 93180yc-fx3 Version-
   CiscoNexus 93180yc-fx3h Version-
   CiscoNexus 93180yc-fx3s Version-
   CiscoNexus 93216tc-fx2 Version-
   CiscoNexus 93240tc-fx2 Version-
   CiscoNexus 93240yc-fx2 Version-
   CiscoNexus 9332c Version-
   CiscoNexus 9332d-gx2b Version-
   CiscoNexus 9332d-h2r Version-
   CiscoNexus 9332pq Version-
   CiscoNexus 9332pq Switch Version-
   CiscoNexus 93360yc-fx2 Version-
   CiscoNexus 9336c-fx2 Version-
   CiscoNexus 9336c-fx2-e Version-
   CiscoNexus 9336pq Version-
   CiscoNexus 9336pq Aci Version-
   CiscoNexus 9336pq Aci Spine Version-
   CiscoNexus 9336pq Aci Spine Switch Version-
   CiscoNexus 9348d-gx2a Version-
   CiscoNexus 9348gc-fx3 Version-
   CiscoNexus 9348gc-fxp Version-
   CiscoNexus 93600cd-gx Version-
   CiscoNexus 9364c Version-
   CiscoNexus 9364c-gx Version-
   CiscoNexus 9364d-gx2a Version-
   CiscoNexus 9372px Version-
   CiscoNexus 9372px-e Version-
   CiscoNexus 9372px-e Switch Version-
   CiscoNexus 9372px Switch Version-
   CiscoNexus 9372tx Version-
   CiscoNexus 9372tx-e Version-
   CiscoNexus 9372tx-e Switch Version-
   CiscoNexus 9372tx Switch Version-
   CiscoNexus 9396px Version-
   CiscoNexus 9396px Switch Version-
   CiscoNexus 9396tx Version-
   CiscoNexus 9396tx Switch Version-
   CiscoNexus 9408 Version-
   CiscoNexus 9432pq Version-
   CiscoNexus 9500 Version-
   CiscoNexus 9500 16-slot Version-
   CiscoNexus 9500 4-slot Version-
   CiscoNexus 9500 8-slot Version-
   CiscoNexus 9500 Supervisor A Version-
   CiscoNexus 9500 Supervisor B Version-
   CiscoNexus 9500r Version-
   CiscoNexus 9504 Version-
   CiscoNexus 9504 Switch Version-
   CiscoNexus 9508 Version-
   CiscoNexus 9508 Switch Version-
   CiscoNexus 9516 Version-
   CiscoNexus 9516 Switch Version-
   CiscoNexus 9536pq Version-
   CiscoNexus 9636pq Version-
   CiscoNexus 9716d-gx Version-
   CiscoNexus 9736pq Version-
   CiscoNexus 9800 Version-
   CiscoNexus 9804 Version-
   CiscoNexus 9808 Version-

10.10.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

HTTP/2 Rapid Reset Attack Vulnerability

Schwachstelle

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).

Beschreibung

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.44% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

https://www.debian.org/security/2023/dsa-5522
Vendor Advisory
Mailing List
https://www.debian.org/security/2023/dsa-5521
Vendor Advisory
Mailing List
https://www.debian.org/security/2023/dsa-5558
Third Party Advisory
Mailing List
https://www.debian.org/security/2023/dsa-5549
Third Party Advisory
Mailing List
https://bugzilla.proxmox.com/show_bug.cgi?id=4988
Third Party Advisory
Issue Tracking
https://github.com/advisories/GHSA-vx74-f528-fxqg
Patch
Vendor Advisory
Mitigation
https://github.com/caddyserver/caddy/issues/5877
Vendor Advisory
Issue Tracking
https://github.com/dotnet/announcements/issues/277
Vendor Advisory
Issue Tracking
Mitigation
https://github.com/micrictor/http2-rst-stream
Third Party Advisory
Exploit
https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
Vendor Advisory
Mailing List
Release Notes
https://news.ycombinator.com/item?id=37830998
Issue Tracking
Press/Media Coverage
https://www.debian.org/security/2023/dsa-5540
Third Party Advisory
Mailing List