HTTP2: HTTP/2 Rapid Reset

This signature detects attempts to exploit a known vulnerability against HTTP/2. A successful attack can result in a denial-of-service condition.

Extended Description

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Affected Products

Cisco crosswork_data_gateway

Short Name
HTTP2:RAPID-RESET
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP2
Keywords
CVE-2023-44487 HTTP/2 Rapid Reset
Release Date
10/12/2023
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3816
False Positive
Occasionally
Vendors

Konghq

Istio

Nghttp2

Projectcontour

Jenkins

Netapp

Varnish_cache_project

Linecorp

Grpc

Amazon

Facebook

Apache

Envoyproxy

Netty

Ietf

Kazu-yamamoto

Eclipse

Caddyserver

Openresty

Cisco

Dena

Akka

Microsoft

Apple

Linkerd

F5

Redhat

Nodejs

Traefik

Fedoraproject

Debian

Golang

Found a potential security threat?