← Back to CVE List
Vulnerability Intelligence Report
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service

CVE-2019-9515

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:87.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-400 ↗CWE-400 Uncontrolled Resource Consumption

Affected Products & Versions

Vendor Product Affected Versions
apple swiftnio all
apple mac_os_x all
canonical ubuntu_linux 16.04, 18.04, 19.04
apache traffic_server all
debian debian_linux 9.0, 10.0
synology skynas all
synology diskstation_manager 6.2
synology vs960hd_firmware all
synology vs960hd all
fedoraproject fedora 29, 30
opensuse leap 15.0, 15.1
redhat jboss_core_services 1.0
redhat jboss_enterprise_application_platform 7.2.0, 7.3.0
redhat openshift_container_platform 4.1
redhat openshift_service_mesh 1.0
redhat openstack 14
redhat quay 3.0.0
redhat single_sign-on 7.3
redhat software_collections 1.0
redhat enterprise_linux 8.0
oracle graalvm 19.2.0
mcafee web_gateway all
f5 big-ip_local_traffic_manager all
nodejs node.js all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
87.806%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2019-03-01T00:00:00
Published2019-08-13T20:50:59
Last Updated2024-08-04T21:54:44

LINK COPIED TO CLIPBOARD