Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-44487

KEV EPSS 94.45% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-44487

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache HTTP/2 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HTTP/2是超文本传输协议的第二版,主要用于保证客户机与服务器之间的通信。 Apache HTTP/2存在安全漏洞。攻击者利用该漏洞导致系统拒绝服务。以下产品和版本受到影响:.NET 6.0,ASP.NET Core 6.0,.NET 7.0,Microsoft Visual Studio 2022 version 17.2,Microsoft Visual Studio 2022 version 17.4,Microsoft Visual Studio 2022 version 17.6,Micros
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2023-44487

#POC DescriptionSource LinkShenlong Link
1Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487https://github.com/bcdannyboy/CVE-2023-44487POC Details
2Proof of concept for DoS exploit https://github.com/imabee101/CVE-2023-44487POC Details
3Test Script for CVE-2023-44487https://github.com/ByteHackr/CVE-2023-44487POC Details
4CVE-2023-44487https://github.com/pabloec20/rapidresetPOC Details
5Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)https://github.com/secengjeff/rapidresetclientPOC Details
6A python based exploit to test out rapid reset attack (CVE-2023-44487)https://github.com/studiogangster/CVE-2023-44487POC Details
7Nonehttps://github.com/ReToCode/golang-CVE-2023-44487POC Details
8HTTP/2 RAPID RESET https://github.com/sigridou/CVE-2023-44487POC Details
9Highly configurable tool to check a server's vulnerability against CVE-2023-44487 by rapidly sending HEADERS and RST_STREAM frames and documenting the server's responses.https://github.com/ndrscodes/http2-rst-stream-attackerPOC Details
10Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concepthttps://github.com/nxenon/cve-2023-44487POC Details
11A tool to check how well a system can handle Rapid Reset DDoS attacks (CVE-2023-44487).https://github.com/terrorist/HTTP-2-Rapid-Reset-ClientPOC Details
12Nonehttps://github.com/sigridou/CVE-2023-44487-POC Details
13Nonehttps://github.com/TYuan0816/cve-2023-44487POC Details
14Nonehttps://github.com/sn130hk/CVE-2023-44487POC Details
15Nonehttps://github.com/threatlabindonesia/CVE-2023-44487-HTTP-2-Rapid-Reset-Exploit-PoCPOC Details
16RapidResetClienthttps://github.com/aulauniversal/CVE-2023-44487POC Details
17POC for CVE-2023-44487https://github.com/BMG-Black-Magic/CVE-2023-44487POC Details
18Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)https://github.com/internalwhel/rapidresetclientPOC Details
19HTTP/2 Rapid Reset Exploit PoChttps://github.com/moften/CVE-2023-44487POC Details
20Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)https://github.com/zanks08/cve-2023-44487-demoPOC Details
21HTTP/2 Rapid Reset Exploit PoChttps://github.com/moften/CVE-2023-44487-HTTP-2-Rapid-Reset-AttackPOC Details
22A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over testing parameters, multiple attack patterns, and advanced monitoring capabilities.https://github.com/madhusudhan-in/CVE_2023_44487-Rapid_ResetPOC Details
23Proof of concept for DoS exploit https://github.com/Appsynergy-io/CVE-2023-44487POC Details
24poc for the rst dos attack discovered in 2023https://github.com/tpirate/cve-2023-44487-POCPOC Details
25PoC for HTTP/2 Rapid Reset DDoS Vulnerability - CVE-2023-44487https://github.com/ReGeLePuMa/HTTP-2-Rapid-Reset-DDosPOC Details
26Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive suite—featuring multi-vector rotations, HTTP/2 Rapid Reset (CVE-2023-44487) exploitation, and mTLS 1.3-encrypted C2 orchestration—with a high-integrity 7-Tier Blue Elite Teaming defense-in-depth architecture.https://github.com/sastraadiwiguna-purpleeliteteaming/DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint-POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-44487

登录查看更多情报信息。

Same Patch Batch · n/a · 2023-10-10 · 23 CVEs total

CVE-2020-27635Multiple Embedded TCP/IP 安全特征问题漏洞
CVE-2023-36126PHPJabbers Appointment Scheduler 跨站脚本漏洞
CVE-2023-36127PHPJabbers Appointment Scheduler 安全漏洞
CVE-2023-45312Ericsson Erlang 安全漏洞
CVE-2023-31096Broadcom LSI PCI-SV92EX Soft Modem Kernel Driver 缓冲区错误漏洞
CVE-2023-43896Macrium Reflect 安全漏洞
CVE-2020-27213Multiple Embedded TCP/IP 安全特征问题漏洞
CVE-2020-27630Multiple Embedded TCP/IP 安全特征问题漏洞
CVE-2020-27631Oryx Embedded CycloneTCP ISN 安全特征问题漏洞
CVE-2020-27633FNET software 安全特征问题漏洞
CVE-2020-27634Contiki 安全特征问题漏洞
CVE-2023-44959D-Link DSL-3782 命令注入漏洞
CVE-2020-27636Microchip MPLAB Net 安全特征问题漏洞
CVE-2023-44763PortlandLabs Concrete CMS 代码问题漏洞
CVE-2023-45208D-Link DAP-X1860 命令注入漏洞
CVE-2023-44846SeaCMS 安全漏洞
CVE-2023-44847SeaCMS 安全漏洞
CVE-2023-44848SeaCMS 安全漏洞
CVE-2020-18336Typora 跨站脚本漏洞
CVE-2023-42189Matter 安全漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-44487

No comments yet


Leave a comment