Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2023-44487KEVEXPLOITEDPATCHED
siemens · simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware

CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many

Description

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Affected Products

VendorProductVersions
siemenssimatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmwaren/a

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
akkahttp_servercve_cpe95%
amazonamazon linuxcert_advisory90%
amazonopensearch_data_preppercve_cpe95%
apacheapisixcve_cpe95%
apachesolrcve_cpe95%

References

  • https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73
  • https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
  • https://aws.amazon.com/security/security-bulletins/AWS-2023-011/
  • https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack
  • https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/
  • https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
  • https://news.ycombinator.com/item?id=37831062
  • https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
  • https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack
  • https://github.com/envoyproxy/envoy/pull/30055
  • https://github.com/haproxy/haproxy/issues/2312
  • https://github.com/eclipse/jetty.project/issues/10679
  • https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764
  • https://github.com/nghttp2/nghttp2/pull/1961
  • https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61
  • https://github.com/alibaba/tengine/issues/1872
  • https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2
  • https://news.ycombinator.com/item?id=37830987
  • https://news.ycombinator.com/item?id=37830998
  • https://github.com/caddyserver/caddy/issues/5877
  • https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/
  • https://github.com/bcdannyboy/CVE-2023-44487
  • https://github.com/grpc/grpc-go/pull/6703
  • https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244
  • https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0
  • https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html
  • https://my.f5.com/manage/s/article/K000137106
  • https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/
  • https://bugzilla.proxmox.com/show_bug.cgi?id=4988
  • https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9
  • http://www.openwall.com/lists/oss-security/2023/10/10/7(mailing-list)
  • http://www.openwall.com/lists/oss-security/2023/10/10/6(mailing-list)
  • https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected
  • https://github.com/microsoft/CBL-Mariner/pull/6381
  • https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
  • https://github.com/facebook/proxygen/pull/466
  • https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
  • https://github.com/micrictor/http2-rst-stream
  • https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve
  • https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/
  • https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf
  • https://github.com/h2o/h2o/pull/3291
  • https://github.com/nodejs/node/pull/50121
  • https://github.com/dotnet/announcements/issues/277
  • https://github.com/golang/go/issues/63417
  • https://github.com/advisories/GHSA-vx74-f528-fxqg
  • https://github.com/apache/trafficserver/pull/10564
  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487
  • https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14
  • https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q
  • https://www.openwall.com/lists/oss-security/2023/10/10/6
  • https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487
  • https://github.com/opensearch-project/data-prepper/issues/3474
  • https://github.com/kubernetes/kubernetes/pull/121120
  • https://github.com/oqtane/oqtane.framework/discussions/3367
  • https://github.com/advisories/GHSA-xpw8-rcwv-8f8p
  • https://netty.io/news/2023/10/10/4-1-100-Final.html
  • https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
  • https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/
  • https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack
  • https://news.ycombinator.com/item?id=37837043
  • https://github.com/kazu-yamamoto/http2/issues/93
  • https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html
  • https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1
  • https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113
  • https://www.debian.org/security/2023/dsa-5522(vendor-advisory)
  • https://www.debian.org/security/2023/dsa-5521(vendor-advisory)
  • https://access.redhat.com/security/cve/cve-2023-44487
  • https://github.com/ninenines/cowboy/issues/1615
  • https://github.com/varnishcache/varnish-cache/issues/3996
  • https://github.com/tempesta-tech/tempesta/issues/1986
  • https://blog.vespa.ai/cve-2023-44487/
  • https://github.com/etcd-io/etcd/issues/16740
  • https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event
  • https://istio.io/latest/news/security/istio-security-2023-004/
  • https://github.com/junkurihara/rust-rpxy/issues/97
  • https://bugzilla.suse.com/show_bug.cgi?id=1216123
  • https://bugzilla.redhat.com/show_bug.cgi?id=2242803
  • https://ubuntu.com/security/CVE-2023-44487
  • https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125
  • https://github.com/advisories/GHSA-qppj-fm5r-hxr3
  • https://github.com/apache/httpd-site/pull/10
  • https://github.com/projectcontour/contour/pull/5826
  • https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632
  • https://github.com/line/armeria/pull/5232
  • https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
  • https://security.paloaltonetworks.com/CVE-2023-44487
  • https://github.com/akka/akka-http/issues/4323
  • https://github.com/openresty/openresty/issues/930
  • https://github.com/apache/apisix/issues/10320
  • https://github.com/Azure/AKS/issues/3947
  • https://github.com/Kong/kong/discussions/11741
  • https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487
  • https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/
  • https://github.com/caddyserver/caddy/releases/tag/v2.7.5
  • https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html(mailing-list)
  • http://www.openwall.com/lists/oss-security/2023/10/13/4(mailing-list)
  • http://www.openwall.com/lists/oss-security/2023/10/13/9(mailing-list)
  • https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/
  • https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/(vendor-advisory)
  • https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/
  • https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html(mailing-list)
  • https://security.netapp.com/advisory/ntap-20231016-0001/
  • https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html(mailing-list)
  • http://www.openwall.com/lists/oss-security/2023/10/18/4(mailing-list)
  • http://www.openwall.com/lists/oss-security/2023/10/18/8(mailing-list)
  • http://www.openwall.com/lists/oss-security/2023/10/19/6(mailing-list)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/(vendor-advisory)
  • http://www.openwall.com/lists/oss-security/2023/10/20/8(mailing-list)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/(vendor-advisory)
  • https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html(mailing-list)
  • https://www.debian.org/security/2023/dsa-5540(vendor-advisory)
  • https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html(mailing-list)
  • https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/(vendor-advisory)
  • https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html(mailing-list)
  • https://www.debian.org/security/2023/dsa-5549(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/(vendor-advisory)
  • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/(vendor-advisory)
  • https://www.debian.org/security/2023/dsa-5558(vendor-advisory)
  • https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html(mailing-list)
  • https://security.gentoo.org/glsa/202311-09(vendor-advisory)
  • https://www.debian.org/security/2023/dsa-5570(vendor-advisory)
  • https://security.netapp.com/advisory/ntap-20240426-0007/
  • https://security.netapp.com/advisory/ntap-20240621-0006/
  • https://security.netapp.com/advisory/ntap-20240621-0007/
  • https://github.com/grpc/grpc/releases/tag/v1.59.2
  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ

Related News (6 articles)

Tier B
BSI Advisories10h ago
[UPDATE] [hoch] Dell ECS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories37d ago
[UPDATE] [hoch] Eclipse Jetty: Mehrere Schwachstellen ermöglichen Denial of Service
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[UPDATE] [mittel] Apache Tomcat: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[UPDATE] [hoch] http/2 Implementierungen: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
Tier B
CERT-FR83d ago
Multiples vulnérabilités dans les produits Splunk (21 mai 2026)
→ No new info (linked only)
Tier B
BSI Advisories118d ago
[UPDATE] [mittel] Red Hat OpenStack: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
golang.org/x/net@0.17.0org.apache.tomcat.embed:tomcat-embed-core@11.0.0-M12org.apache.tomcat.embed:tomcat-embed-core@10.1.14org.apache.tomcat.embed:tomcat-embed-core@9.0.81org.apache.tomcat.embed:tomcat-embed-core@8.5.94github.com/apple/swift-nio-http2@1.28.0org.eclipse.jetty.http2:http2-common@9.4.53org.eclipse.jetty.http2:http2-common@10.0.17org.eclipse.jetty.http2:http2-common@11.0.17org.eclipse.jetty.http2:http2-server@9.4.53org.eclipse.jetty.http2:http2-server@10.0.17org.eclipse.jetty.http2:http2-server@11.0.17org.eclipse.jetty.http2:jetty-http2-common@12.0.2org.eclipse.jetty.http2:jetty-http2-server@12.0.2com.typesafe.akka:akka-http-core@10.5.3com.typesafe.akka:akka-http-core_2.13@10.5.3com.typesafe.akka:akka-http-core_2.12@10.5.3org.apache.tomcat:tomcat-coyote@11.0.0-M12org.apache.tomcat:tomcat-coyote@10.1.14org.apache.tomcat:tomcat-coyote@9.0.81org.apache.tomcat:tomcat-coyote@8.5.94
PublishedOct 10, 2023
Last enriched132d ago
Trending Score128🔥
Source articles6
Independent2
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-58115
CVE-2026-58115: A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In
Trending: 39
MEDIUMCVE-2026-59693
CVE-2026-59693: A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.
Trending: 32
HIGHCVE-2026-50063
CVE-2026-50063: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
Trending: 29
HIGHCVE-2026-50061
CVE-2026-50061: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
Trending: 29
HIGHCVE-2026-50064
CVE-2026-50064: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
Trending: 29

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Oct 10, 2023
Added to CISA KEV
Oct 10, 2023
Discovered by ZDM
Apr 1, 2026
Actively Exploited
Jul 14, 2026
Exploit Available
Jul 14, 2026
Patch Available
Jul 14, 2026