EXPOSURES › CVE-2023-44487
CVE-2023-44487
HIGH ⌖ ON CISA KEV · EXPLOITEDHTTP/2 Rapid Reset Attack Vulnerability allows DDoS attacks.
The HTTP/2 protocol contains a rapid reset vulnerability that can be exploited to launch distributed denial-of-service (DDoS) attacks. This vulnerability is actively exploited and poses a significant risk to systems using HTTP/2. DIB organizations should ensure they are using updated versions of HTTP/2 to mitigate this risk.
Shame score — The vulnerability is actively exploited and allows for a DDoS attack, which can significantly impact system availability and security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).