peter bassill · operator
$ cve CVE-2023-44487 JSON

CVE-2023-44487 KEV EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-10-31.

Description

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-400
On CISA KEVyes — remediate by 2023-10-31
Public exploityes
Published2023-10-10
Last modified2026-08-11

CISA KEV

NameHTTP/2 Rapid Reset Attack Vulnerability
Added2023-10-10
Due2023-10-31
Vendor / productIETF / HTTP/2
Ransomware usenone reported

Affected (40)

VendorProduct
caddyservercaddy
eclipsejetty
envoyproxyenvoy
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip advanced web application firewall
f5big-ip analytics
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip application visibility and reporting
f5big-ip carrier-grade nat
f5big-ip ddos hybrid defender
f5big-ip domain name system
f5big-ip fraud protection service
f5big-ip global traffic manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip next
f5big-ip next service proxy for kubernetes
f5big-ip policy enforcement manager
f5big-ip ssl orchestrator
f5big-ip webaccelerator
f5big-ip websafe
golanggo
golanghttp2
golangnetworking
ietfhttp
nettynetty
nghttp2nghttp2
siemensruggedcom ape1808
siemensruggedcom ape1808 firmware
siemenssimatic s7-1500 cpu 1518-4 pn\/dp
siemenssimatic s7-1500 cpu 1518-4 pn\/dp mfp firmware
siemenssimatic s7-1500 cpu 1518f-4 pn\/dp mfp
siemenssimatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware
siemenssinec ins
siemenssinec nms
siemenssiplus s7-1500 cpu 1518-4 pn\/dp mfp
siemenssiplus s7-1500 cpu 1518-4 pn\/dp mfp firmware
siemensst7 scadaconnect

Public exploits

SourceTitleDate
exploit-dbHTTP/2 2.0 - Denial Of Service (DOS)2025-09-16

References

→ the Explorer  ·  watch your stack  ·  NVD