CVE-2023-44487
HTTP/2 Rapid Reset Attack Vulnerability
Beschreibung
CVE-2023-44487 ist eine Schwachstelle im HTTP/2-Protokoll, die als "HTTP/2 Rapid Reset" bekannt wurde und eine unkontrollierte Ressourcenerschoepfung (Denial of Service) ermoeglicht. Die Sicherheitsluecke betrifft nahezu alle Webserver und Reverse-Proxies, die HTTP/2 unterstuetzen, darunter Produkte von IETF, nghttp2, Netty, Envoy, Eclipse Jetty, Caddy, Golang und zahlreiche F5 BIG-IP-Module. Ein Angreifer kann durch schnelles Oeffnen und sofortiges Zuruecksetzen (RST_STREAM) einer grossen Anzahl von HTTP/2-Streams die Serverressourcen ueberlasten und so einen Denial-of-Service-Zustand ausloesen. Diese Schwachstelle wurde von August bis Oktober 2023 aktiv in freier Wildbahn ausgenutzt, ist im KEV-Katalog der CISA gelistet und erreicht mit einem EPSS-Score von 94,4 % (99,97. Perzentil) eine nahezu sichere Ausnutzungswahrscheinlichkeit.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HIm Rechner öffnenBetroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| siemens | simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware | >= 3.1.5 |
| siemens | sinec ins | < 1.0; 1.0 |
| siemens | sinec nms | < 3.0 |
| siemens | st7 scadaconnect | < 1.1 |
| siemens | ruggedcom ape1808 firmware | - |
| siemens | simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware | >= 3.1.5 |
| siemens | siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware | >= 3.1.5 |
| ietf | http | 2.0 |
| nghttp2 | nghttp2 | < 1.57.0 |
| netty | netty | < 4.1.100 |
| envoyproxy | envoy | 1.24.10; 1.25.9; 1.26.4; 1.27.0 |
| eclipse | jetty | < 9.4.53; >= 10.0.0, < 10.0.17; >= 11.0.0, < 11.0.17; >= 12.0.0, < 12.0.2 |
| caddyserver | caddy | < 2.7.5 |
| golang | go | < 1.20.10; >= 1.21.0, < 1.21.3 |
| golang | http2 | < 0.17.0 |
| golang | networking | < 0.17.0 |
| f5 | big-ip access policy manager | >= 13.1.0, <= 13.1.5; >= 14.1.0, <= 14.1.5; >= 15.1.0, <= 15.1.10; >= 16.1.0, <= 16.1.4; 17.1.0 |
| f5 | big-ip advanced firewall manager | >= 13.1.0, <= 13.1.5; >= 14.1.0, <= 14.1.5; >= 15.1.0, <= 15.1.10; >= 16.1.0, <= 16.1.4; 17.1.0 |
| f5 | big-ip advanced web application firewall | >= 13.1.0, <= 13.1.5; >= 14.1.0, <= 14.1.5; >= 15.1.0, <= 15.1.10; >= 16.1.0, <= 16.1.4; 17.1.0 |
| f5 | big-ip analytics | >= 13.1.0, <= 13.1.5; >= 14.1.0, <= 14.1.5; >= 15.1.0, <= 15.1.10; >= 16.1.0, <= 16.1.4; 17.1.0 |
Mehrere CVSS-Bewertungen
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Referenzen
- http://www.openwall.com/lists/oss-security/2023/10/10/6(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/10/7(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/13/4(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/13/9(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/18/4(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/18/8(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/19/6(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/20/8(Mailing List, Third Party Advisory)
- https://access.redhat.com/security/cve/cve-2023-44487(Vendor Advisory)
- https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/(Press/Media Coverage, Third Party Advisory)
- https://aws.amazon.com/security/security-bulletins/AWS-2023-011/(Third Party Advisory)
- https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/(Technical Description, Vendor Advisory)
- https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/(Third Party Advisory, Vendor Advisory)
- https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/(Vendor Advisory)
- https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack(Press/Media Coverage, Third Party Advisory)
- https://blog.vespa.ai/cve-2023-44487/(Vendor Advisory)
- https://bugzilla.proxmox.com/show_bug.cgi?id=4988(Issue Tracking, Third Party Advisory)
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803(Issue Tracking, Vendor Advisory)
- https://bugzilla.suse.com/show_bug.cgi?id=1216123(Issue Tracking, Vendor Advisory)
- https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9(Mailing List, Patch, Vendor Advisory)
- https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/(Technical Description, Vendor Advisory)
- https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack(Technical Description, Vendor Advisory)
- https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125(Vendor Advisory)
- https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715(Third Party Advisory)
- https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve(Broken Link)
- https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764(Vendor Advisory)
- https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088(Issue Tracking, Patch)
- https://github.com/Azure/AKS/issues/3947(Issue Tracking)
- https://github.com/Kong/kong/discussions/11741(Issue Tracking)
- https://github.com/advisories/GHSA-qppj-fm5r-hxr3(Vendor Advisory)
- https://github.com/advisories/GHSA-vx74-f528-fxqg(Mitigation, Patch, Vendor Advisory)
- https://github.com/advisories/GHSA-xpw8-rcwv-8f8p(Patch, Vendor Advisory)
- https://github.com/akka/akka-http/issues/4323(Issue Tracking)
- https://github.com/alibaba/tengine/issues/1872(Issue Tracking)
- https://github.com/apache/apisix/issues/10320(Issue Tracking)
- https://github.com/apache/httpd-site/pull/10(Issue Tracking)
- https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113(Product)
- https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2(Product, Third Party Advisory)
- https://github.com/apache/trafficserver/pull/10564(Issue Tracking, Patch)
- https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487(Vendor Advisory)
- https://github.com/bcdannyboy/CVE-2023-44487(Third Party Advisory)
- https://github.com/caddyserver/caddy/issues/5877(Issue Tracking, Vendor Advisory)
- https://github.com/caddyserver/caddy/releases/tag/v2.7.5(Release Notes, Third Party Advisory)
- https://github.com/dotnet/announcements/issues/277(Issue Tracking, Mitigation, Vendor Advisory)
- https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73(Product, Release Notes)
- https://github.com/eclipse/jetty.project/issues/10679(Issue Tracking)
- https://github.com/envoyproxy/envoy/pull/30055(Issue Tracking, Patch)
- https://github.com/etcd-io/etcd/issues/16740(Issue Tracking, Patch)
- https://github.com/facebook/proxygen/pull/466(Issue Tracking, Patch)
- https://github.com/golang/go/issues/63417(Issue Tracking)
- https://github.com/grpc/grpc-go/pull/6703(Issue Tracking, Patch)
- https://github.com/grpc/grpc/releases/tag/v1.59.2(Mailing List)
- https://github.com/h2o/h2o/pull/3291(Issue Tracking, Patch)
- https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf(Vendor Advisory)
- https://github.com/haproxy/haproxy/issues/2312(Issue Tracking)
- https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244(Product)
- https://github.com/junkurihara/rust-rpxy/issues/97(Issue Tracking)
- https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1(Patch)
- https://github.com/kazu-yamamoto/http2/issues/93(Issue Tracking)
- https://github.com/kubernetes/kubernetes/pull/121120(Issue Tracking, Patch)
- https://github.com/line/armeria/pull/5232(Issue Tracking, Patch)
- https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632(Patch)
- https://github.com/micrictor/http2-rst-stream(Exploit, Third Party Advisory)
- https://github.com/microsoft/CBL-Mariner/pull/6381(Issue Tracking, Patch)
- https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61(Patch)
- https://github.com/nghttp2/nghttp2/pull/1961(Issue Tracking, Patch)
- https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0(Release Notes)
- https://github.com/ninenines/cowboy/issues/1615(Issue Tracking)
- https://github.com/nodejs/node/pull/50121(Issue Tracking)
- https://github.com/openresty/openresty/issues/930(Issue Tracking)
- https://github.com/opensearch-project/data-prepper/issues/3474(Issue Tracking, Patch)
- https://github.com/oqtane/oqtane.framework/discussions/3367(Issue Tracking)
- https://github.com/projectcontour/contour/pull/5826(Issue Tracking, Patch)
- https://github.com/tempesta-tech/tempesta/issues/1986(Issue Tracking)
- https://github.com/varnishcache/varnish-cache/issues/3996(Issue Tracking)
- https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo(Mailing List, Release Notes, Vendor Advisory)
- https://istio.io/latest/news/security/istio-security-2023-004/(Vendor Advisory)
- https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/(Vendor Advisory)
- https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html(Mailing List, Third Party Advisory)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/(Mailing List)
- https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html(Mailing List, Third Party Advisory)
- https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html(Mailing List, Patch, Third Party Advisory)
- https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html(Third Party Advisory)
- https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/(Patch, Vendor Advisory)
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487(Mitigation, Patch, Vendor Advisory)
- https://my.f5.com/manage/s/article/K000137106(Vendor Advisory)
- https://netty.io/news/2023/10/10/4-1-100-Final.html(Release Notes, Vendor Advisory)
- https://news.ycombinator.com/item?id=37830987(Issue Tracking)
- https://news.ycombinator.com/item?id=37830998(Issue Tracking, Press/Media Coverage)
- https://news.ycombinator.com/item?id=37831062(Issue Tracking)
- https://news.ycombinator.com/item?id=37837043(Issue Tracking)
- https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/(Third Party Advisory)
- https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected(Third Party Advisory)
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ(Vendor Advisory)
- https://security.gentoo.org/glsa/202311-09(Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20231016-0001/(Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20240426-0007/(Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20240621-0006/(Exploit, Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20240621-0007/(Third Party Advisory)
- https://security.paloaltonetworks.com/CVE-2023-44487(Vendor Advisory)
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14(Release Notes)
- https://ubuntu.com/security/CVE-2023-44487(Vendor Advisory)
- https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/(Third Party Advisory)
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487(Third Party Advisory, US Government Resource)
- https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event(Press/Media Coverage, Third Party Advisory)
- https://www.debian.org/security/2023/dsa-5521(Mailing List, Vendor Advisory)
- https://www.debian.org/security/2023/dsa-5522(Mailing List, Vendor Advisory)
- https://www.debian.org/security/2023/dsa-5540(Mailing List, Third Party Advisory)
- https://www.debian.org/security/2023/dsa-5549(Mailing List, Third Party Advisory)
- https://www.debian.org/security/2023/dsa-5558(Mailing List, Third Party Advisory)
- https://www.debian.org/security/2023/dsa-5570(Third Party Advisory)
- https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487(Third Party Advisory, Vendor Advisory)
- https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/(Vendor Advisory)
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/(Mitigation, Vendor Advisory)
- https://www.openwall.com/lists/oss-security/2023/10/10/6(Mailing List, Third Party Advisory)
- https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack(Press/Media Coverage)
- https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/(Press/Media Coverage, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2025/08/13/6(Third Party Advisory)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/(Mailing List, Third Party Advisory)
- https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-341067.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-784301.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-832273.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-915275.html(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487(US Government Resource)
Schwachstellentyp
CWE-400: Uncontrolled Resource Consumption
Bei CVE-2023-44487 manifestiert sich die unkontrollierte Ressourcenerschoepfung darin, dass das HTTP/2-Protokoll es erlaubt, eine grosse Anzahl von Streams in schneller Folge zu oeffnen und sofort wieder zurueckzusetzen, wodurch der Server erhebliche Rechenleistung fuer die Verarbeitung und Bereinigung dieser Streams aufwenden muss, ohne dass der Client nennenswerte Ressourcen verbraucht. Diese Asymmetrie zwischen Client- und Serveraufwand fuehrt zu einer effektiven Denial-of-Service-Attacke.
Mehr erfahren: CWE-400 -- Uncontrolled Resource Consumption
Auswirkungsanalyse
CVE-2023-44487 ist mit einem CVSS-Score von 7.5 (HIGH) bewertet und ueber das Netzwerk ohne physischen Zugang ausnutzbar. Die Angriffsomplexitaet ist gering, es werden keine Berechtigungen oder Benutzerinteraktionen benoetigt, was die Schwachstelle besonders leicht ausnutzbar macht. Verfuegbarkeit (Hoch): Der primaere Einfluss liegt auf der Verfuegbarkeit -- betroffene Server koennen durch die Rapid-Reset-Attacke vollstaendig ueberlastet und fuer legitime Benutzer unerreichbar gemacht werden. Vertraulichkeit und Integritaet sind nicht direkt betroffen (beide NONE). Der EPSS-Score von 94,4 % weist auf eine extrem hohe Wahrscheinlichkeit aktiver Ausnutzung hin, was durch die dokumentierte Ausnutzung in der Praxis mit rekordverdaechtigen DDoS-Angriffen bestaetigt wird.
Exploit-Reifegrad
Oeffentlicher Exploit-Code ist verfuegbar fuer CVE-2023-44487, unter anderem ueber GitHub (micrictor) und NetApp Advisory. Die CISA hat die aktive Ausnutzung in freier Wildbahn bestaetigt und die Schwachstelle in den KEV-Katalog aufgenommen, wobei der Ransomware-Status als "Unknown" eingestuft ist. Der EPSS-Score von 94,4 % (99,97. Perzentil) weist auf eine nahezu sichere Ausnutzungsaktivitaet hin, was durch die dokumentierten rekordverdaechtigen DDoS-Angriffe von August bis Oktober 2023 untermauert wird.
Behebung
- Sofortige Patches anwenden: Gemaess CISA-Vorgabe (Frist: 31.10.2023) muessen Abmilderungsmassnahmen gemaess den Herstelleranweisungen umgesetzt oder das betroffene Produkt ausser Betrieb genommen werden. Aktualisieren Sie alle HTTP/2-faehigen Server und Reverse-Proxies auf gepatchte Versionen (z. B. nghttp2 >= 1.57.0, Netty >= 4.1.100, Caddy >= 2.7.5, Go-Standardbibliothek mit aktuellen Patches).
- HTTP/2-Stream-Limits konfigurieren: Begrenzen Sie die maximale Anzahl gleichzeitiger Streams und die Rate, mit der neue Streams geoeffnet werden koennen, auf Serverebene (z. B. SETTINGS_MAX_CONCURRENT_STREAMS und RST_STREAM-Rate-Limiting).
- Rate-Limiting und DDoS-Schutz aktivieren: Setzen Sie WAF-Regeln und Load-Balancer ein, die ungewoehnlich hohe Stream-Reset-Raten erkennen und blockieren. Cloud-basierte DDoS-Schutzdienste (z. B. Cloudflare, AWS Shield) bieten spezifische Abmilderungen fuer HTTP/2 Rapid Reset.
- Monitoring und Protokollanalyse: Ueberwachen Sie HTTP/2-Verbindungsmetriken auf ungewoehnlich hohe RST_STREAM-Raten. Pruefen Sie Webserver-Logs auf Anzeichen von Rapid-Reset-Angriffen und konfigurieren Sie Alarme fuer ploetzliche Anstiege der Verbindungszahlen.
- Fallback auf HTTP/1.1 als Notfallmassnahme: Falls Patches nicht sofort verfuegbar sind, kann als voruebergehende Massnahme HTTP/2 deaktiviert und auf HTTP/1.1 zurueckgefallen werden, um die Angriffsflaeche zu eliminieren.
Technische Details
CVE-2023-44487 nutzt eine Designschwaeche im HTTP/2-Protokoll aus, die als unkontrollierte Ressourcenerschoepfung (CWE-400) klassifiziert wird. Der Angriff funktioniert, indem ein Client eine grosse Anzahl von HTTP/2-Streams oeffnet (HEADERS-Frame) und diese sofort mit einem RST_STREAM-Frame zuruecksetzt, bevor der Server die Anfrage vollstaendig verarbeitet hat. Der CVSS-Vektor (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) bestaetigt, dass der Angriff remote, ohne Authentifizierung und ohne Benutzerinteraktion durchfuehrbar ist und ausschliesslich die Verfuegbarkeit beeintraechtigt. Da die Verarbeitung und Bereinigung eines Streams auf Serverseite deutlich mehr Ressourcen verbraucht als das Senden eines RST_STREAM-Frames auf Clientseite, entsteht eine massive Asymmetrie, die es einem einzelnen Client ermoeglicht, selbst leistungsstarke Server zu ueberlasten. Diese Schwachstelle betrifft das HTTP/2-Protokoll selbst und damit praktisch jede Implementierung, die keine expliziten Rate-Limits fuer Stream-Resets durchsetzt.
Häufig gestellte Fragen
Wird CVE-2023-44487 aktiv ausgenutzt?
Ja, CVE-2023-44487 wird aktiv ausgenutzt und ist im KEV-Katalog (Known Exploited Vulnerabilities) der CISA gelistet. Die Schwachstelle wurde von August bis Oktober 2023 fuer rekordverdaechtige DDoS-Angriffe missbraucht. Der EPSS-Score von 94,4 % (99,97. Perzentil) bestaetigt die extrem hohe Ausnutzungswahrscheinlichkeit.
Welche Produkte sind von CVE-2023-44487 betroffen?
CVE-2023-44487 betrifft praktisch alle Webserver und Reverse-Proxies mit HTTP/2-Unterstuetzung. Zu den bekannten betroffenen Produkten gehoeren unter anderem nghttp2, Netty, Envoy Proxy, Eclipse Jetty, Caddy, Golang HTTP/2-Implementierungen sowie zahlreiche F5 BIG-IP-Module. Da es sich um eine Protokollschwaeche handelt, sind potenziell alle HTTP/2-Implementierungen betroffen.
Wie behebe ich CVE-2023-44487?
Aktualisieren Sie alle betroffenen HTTP/2-Server und -Bibliotheken auf die neuesten gepatchten Versionen. Konfigurieren Sie Stream-Limits und RST_STREAM-Rate-Limiting auf Serverebene. Detaillierte Schritte finden Sie im Abschnitt Behebung.
Wie schwerwiegend ist CVE-2023-44487?
CVE-2023-44487 hat einen CVSS-Score von 7.5 (HIGH) und liegt mit einem EPSS-Perzentil von 99,97 % in der Spitzengruppe der am haeufigsten ausgenutzten Schwachstellen. Obwohl nur die Verfuegbarkeit betroffen ist, kann die Schwachstelle zu vollstaendigen Dienstausfaellen fuehren und wurde fuer die groessten jemals gemessenen DDoS-Angriffe eingesetzt.
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.