[CISCO-SA-HTTP2-RESET-D8KF32VZ] HTTP/2 Rapid Reset Attack Affecting Cisco Products: October 2023

Severity High
CVEs 1

On October 10, 2023, the following HTTP/2 protocol-level weakness, which enables a novel distributed denial of service (DDoS) attack technique, was disclosed:

CVE-2023-44487: HTTP/2 Rapid Reset

For a description of this vulnerability, see the following publications:

How it works: The novel HTTP/2 'Rapid Reset' DDoS attack "https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack"
HTTP/2 Zero-Day vulnerability results in record-breaking DDoS attacks "https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/"
CVE-2023-44487 - HTTP/2 Rapid Reset Attack "https://aws.amazon.com/security/security-bulletins/AWS-2023-011/"

ID
CISCO-SA-HTTP2-RESET-D8KF32VZ
Severity
high
URL
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ
Published
2023-10-16T16:00:00
(11 months ago)
Modified
2023-10-16T16:00:00
(11 months ago)
Rights
Cisco Systems, Inc.
Other Advisories
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...