← לוח פגיעויות

CVE-2023-44487

גבוהה 7.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
HTTP/2 Rapid Reset Attack Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-400

מוצרים מושפעים

siemens: simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware; siemens: simatic s7-1500 cpu 1518f-4 pn\/dp mfp; siemens: sinec ins; siemens: sinec nms; siemens: st7 scadaconnect; siemens: ruggedcom ape1808 firmware; siemens: ruggedcom ape1808; siemens: simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware; siemens: simatic s7-1500 cpu 1518-4 pn\/dp; siemens: siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware; siemens: siplus s7-1500 cpu 1518-4 pn\/dp mfp; ietf: http; nghttp2: nghttp2; netty: netty; envoyproxy: envoy

קישורים