The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
| Vendor | Product | Versions |
|---|---|---|
| siemens | simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware | n/a |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| akka | http_server | cve_cpe | 95% |
| amazon | amazon linux | cert_advisory | 90% |
| amazon | opensearch_data_prepper | cve_cpe | 95% |
| apache | apisix | cve_cpe | 95% |
| apache | solr | cve_cpe | 95% |