Skip to content
Appaloosa Scout

KEV · Actively exploited

CVE-2023-44487

HIGH 7.5 KEV

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS 100.00% exploit likely percentile 100.0%

CISA Known Exploited Vulnerability

Added to KEV
2023-10-10
Remediation deadline
2023-10-31
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware
Unknown (not documented by CISA)

OS versions that fix this CVE

This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.

View on NVD ↗ CISA KEV catalog ↗ Advisory · github.com Advisory · msrc.microsoft.com Advisory · cgit.freebsd.org