CVE-2023-44487 – HTTP/2 Rapid Reset Attack

Publication Date: 2023/10/10 05:00 AM PDT AWS is aware of CVE-2023-44487, also known as "HTTP/2 Rapid Reset Attack," related to HTTP/2 capable web servers where rapid stream generation and cancellation can result in additional load which could lead to a Denial of Service. AWS infrastructure is designed with various protections to address Layer 7 request floods, we have implemented additional mitigations to address this issue. AWS also recommends customers who operate their own HTTP/2 More info: https://aws.amazon.com/security/security-bulletins/AWS-2023-011/

K20307245 : BIG-IP tmsh vulnerability CVE-2023-45219

Security Advisory Description Exposure of Sensitive Information vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command, which may allow an authenticated attacker with resource ... More info: https://my.f5.com/manage/s/article/K20307245?utm_source=f5support&utm_medium=RSS

K000137053 : Overview of F5 vulnerabilities (October 2023)

Security Advisory Description Note: F5 is committed to responding quickly to potential vulnerabilities in F5 products. As with all publicly known vulnerabilities, F5 is committed to publishing a ... More info: https://my.f5.com/manage/s/article/K000137053?utm_source=f5support&utm_medium=RSS

K000137106 : HTTP/2 vulnerability CVE-2023-44487

Security Advisory Description This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available. Learn more about the ... More info: https://my.f5.com/manage/s/article/K000137106?utm_source=f5support&utm_medium=RSS

K20307245 : BIG-IP tmsh vulnerability CVE-2023-45219

Security Advisory Description Exposure of Sensitive Information vulnerability exists in an undisclosed BIG-IP TMOS shell (tmsh) command, which may allow an authenticated attacker with resource ... More info: https://my.f5.com/manage/s/article/K20307245?utm_source=f5support&utm_medium=RSS

K000137186 : Linux kernel vulnerability CVE-2022-3564

Security Advisory Description A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_ ... More info: https://my.f5.com/manage/s/article/K000137186?utm_source=f5support&utm_medium=RSS

K000137188 : AMD CPU vulnerability CVE-2021-26401

Security Advisory Description LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. (CVE-2021-26401) Impact There is no impact; F5 products are not affected by ... More info: https://my.f5.com/manage/s/article/K000137188?utm_source=f5support&utm_medium=RSS
Translate »