Skip to content
COOEY

EXPOSURES › CVE-2023-44487

CVE-2023-44487

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-10-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-44487 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

HTTP/2 Rapid Reset Attack Vulnerability allows DDoS attacks.

The HTTP/2 protocol contains a rapid reset vulnerability that can be exploited to launch distributed denial-of-service (DDoS) attacks. This vulnerability is actively exploited and poses a significant risk to systems using HTTP/2. DIB organizations should ensure they are using updated versions of HTTP/2 to mitigate this risk.

Shame score — The vulnerability is actively exploited and allows for a DDoS attack, which can significantly impact system availability and security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.