HIGH · 7.5

CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Vulnerability Description

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
SiemensSimatic S7-1500 Cpu 1518F-4 Pn\/Dp Mfp Firmware>= 3.1.5
SiemensSimatic S7-1500 Cpu 1518F-4 Pn\/Dp Mfp-
SiemensSinec Ins< 1.0
SiemensSinec Nms< 3.0
SiemensSt7 Scadaconnect< 1.1
SiemensRuggedcom Ape1808 Firmware-
SiemensRuggedcom Ape1808-
SiemensSimatic S7-1500 Cpu 1518-4 Pn\/Dp Mfp Firmware>= 3.1.5
SiemensSimatic S7-1500 Cpu 1518-4 Pn\/Dp-
SiemensSiplus S7-1500 Cpu 1518-4 Pn\/Dp Mfp Firmware>= 3.1.5
SiemensSiplus S7-1500 Cpu 1518-4 Pn\/Dp Mfp-
IetfHttp2.0
Nghttp2Nghttp2< 1.57.0
NettyNetty< 4.1.100
EnvoyproxyEnvoy1.24.10
EclipseJetty< 9.4.53
CaddyserverCaddy< 2.7.5
GolangGo< 1.20.10
GolangHttp2< 0.17.0
GolangNetworking< 0.17.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-44487?

CVE-2023-44487 is a vulnerability with a CVSS score of 7.5 (HIGH). The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

How severe is CVE-2023-44487?

CVE-2023-44487 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-44487?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic S7-1500 Cpu 1518F-4 Pn\/Dp Mfp Firmware, Siemens Simatic S7-1500 Cpu 1518F-4 Pn\/Dp Mfp, Siemens Sinec Ins, Siemens Sinec Nms, Siemens St7 Scadaconnect.