Lucene search

K
ciscoCiscoCISCO-SA-HTTP2-RESET-D8KF32VZ
HistoryOct 16, 2023 - 4:00 p.m.

HTTP/2 Rapid Reset Attack Affecting Cisco Products: October 2023

2023-10-1616:00:00
tools.cisco.com
44
http/2
vulnerability
cisco products
ddos attack
rapid reset
security advisory
zero-day

AI Score

7.2

Confidence

High

EPSS

0.816

Percentile

98.4%

On October 10, 2023, the following HTTP/2 protocol-level weakness, which enables a novel distributed denial of service (DDoS) attack technique, was disclosed:

CVE-2023-44487: HTTP/2 Rapid Reset

For a description of this vulnerability, see the following publications:

How it works: The novel HTTP/2 ‘Rapid Reset’ DDoS attack [“https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack”] (Google)
HTTP/2 Zero-Day vulnerability results in record-breaking DDoS attacks [“https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/”] (Cloudflare)
CVE-2023-44487 - HTTP/2 Rapid Reset Attack [“https://aws.amazon.com/security/security-bulletins/AWS-2023-011/”] (AWS)

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ”]

Affected configurations

Vulners
Node
ciscounified_contact_center_enterpriseMatchany
OR
ciscocisco_nx-os_softwareMatchany
OR
ciscosecure_web_appliance_firmwareMatchany
OR
ciscoprime_network_registrarMatchany
OR
ciscotelepresence_video_communication_serverMatchanyexpressway
OR
ciscoevolved_programmable_network_managerMatchany
OR
ciscoenterprise_chat_and_emailMatchany
OR
ciscoprime_cable_provisioningMatchany
OR
ciscoultra_cloud_core_-_session_management_functionMatchany
OR
ciscocisco_wae_automationMatchany
OR
ciscomate_collectorMatchany
OR
ciscounified_contact_center_enterpriseMatchany
OR
ciscocisco_nx-os_softwareMatchany
OR
ciscosecure_web_appliance_firmwareMatchany
OR
ciscoprime_network_registrarMatchany
OR
ciscotelepresence_video_communication_serverMatchanyexpressway
OR
ciscoevolved_programmable_network_managerMatchany
OR
ciscoenterprise_chat_and_emailMatchany
OR
ciscoprime_cable_provisioningMatchany
OR
ciscoultra_cloud_core_-_session_management_functionMatchany
OR
ciscocisco_wae_automationMatchany
OR
ciscomate_collectorMatchany
VendorProductVersionCPE
ciscounified_contact_center_enterpriseanycpe:2.3:a:cisco:unified_contact_center_enterprise:any:*:*:*:*:*:*:*
ciscocisco_nx-os_softwareanycpe:2.3:a:cisco:cisco_nx-os_software:any:*:*:*:*:*:*:*
ciscosecure_web_appliance_firmwareanycpe:2.3:o:cisco:secure_web_appliance_firmware:any:*:*:*:*:*:*:*
ciscoprime_network_registraranycpe:2.3:a:cisco:prime_network_registrar:any:*:*:*:*:*:*:*
ciscotelepresence_video_communication_serveranycpe:2.3:a:cisco:telepresence_video_communication_server:any:*:*:*:expressway:*:*:*
ciscoevolved_programmable_network_manageranycpe:2.3:a:cisco:evolved_programmable_network_manager:any:*:*:*:*:*:*:*
ciscoenterprise_chat_and_emailanycpe:2.3:a:cisco:enterprise_chat_and_email:any:*:*:*:*:*:*:*
ciscoprime_cable_provisioninganycpe:2.3:a:cisco:prime_cable_provisioning:any:*:*:*:*:*:*:*
ciscoultra_cloud_core_-_session_management_functionanycpe:2.3:a:cisco:ultra_cloud_core_-_session_management_function:any:*:*:*:*:*:*:*
ciscocisco_wae_automationanycpe:2.3:a:cisco:cisco_wae_automation:any:*:*:*:*:*:*:*
Rows per page:
1-10 of 111