Vulnerability record · CVE-2023-44487 · published 10 October 2023
CVE-2023-44487: HTTP/2 Rapid Reset stream cancellation denial of service
Siemens · Simatic S7 1500 Cpu 1518f 4 Pn\/Dp Mfp Firmware
The HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. This enables a denial of service against HTTP/2 servers and was exploited in the wild from August through October 2023.
Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
critical priorityIt is in CISA KEV with confirmed in-the-wild exploitation, an EPSS near 1.0, and a network-reachable unauthenticated denial of service affecting a broad set of HTTP/2 products.
What it is
The HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. This enables a denial of service against HTTP/2 servers and was exploited in the wild from August through October 2023.
Impact
An unauthenticated remote attacker can exhaust server CPU and memory, degrading or taking down HTTP/2 services. No data confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reachable over the network via HTTP/2 connections; the CVSS vector shows no privileges or user interaction required. Any exposed HTTP/2 endpoint, including proxies, load balancers and application servers, is in scope.
Exploitation
CISA added it to KEV on 2023-10-10 with a 2023-10-31 due date, and EPSS is 0.99999 (99.999th percentile); the description states it was exploited in the wild. No ransomware campaign use is recorded.
What to do
- Apply vendor patches or configuration mitigations for every HTTP/2 implementation in the environment (servers, proxies, load balancers, service meshes).
- If a patch is unavailable, follow the vendor's interim guidance, which may include limiting concurrent streams or disabling HTTP/2.
- Inventory all internet-facing HTTP/2 endpoints and confirm each has been remediated.
- Apply rate limiting and connection/stream caps at the edge to blunt rapid-reset floods.
- Track the CISA KEV due date and BOD 22-01 requirements for cloud services.
Detection
- Monitor for spikes in HTTP/2 RST_STREAM frames or stream cancellations per connection.
- Alert on abnormal concurrent stream counts and rapid connect/reset patterns from single clients.
- Watch server CPU and memory saturation correlated with HTTP/2 traffic surges.
- Review edge and load balancer logs for high-volume short-lived HTTP/2 streams.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-44487 to the Known Exploited Vulnerabilities catalog on 10 October 2023 as "HTTP/2 Rapid Reset Attack Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 31 October 2023.
Affected products
150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-44487 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-44487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.