Lucene search

K
f5F5F5:K98053339
HistoryAug 20, 2019 - 12:00 a.m.

K98053339 : HTTP/2 Ping Flood vulnerability CVE-2019-9512

2019-08-2000:00:00
my.f5.com
29

7.2 High

AI Score

Confidence

High

0.154 Low

EPSS

Percentile

95.9%

Security Advisory Description

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both. (CVE-2019-9512)

Impact

The BIG-IP system may exhaust available resources and fail over to another system in the device group.