CVE-2019-9515
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Affected (41)
Show all products
Apple: Swiftnio · Apache: Traffic Server · Canonical: Ubuntu Linux · Debian: Debian Linux · Synology: Diskstation Manager, Skynas, Vs960hd Firmware · Fedoraproject: Fedora · Opensuse: Leap · Redhat: Enterprise Linux, Jboss Core Services, Jboss Enterprise Application Platform, Openshift Container Platform, Openshift Service Mesh, Openstack, Quay, Single Sign On, Software Collections · Oracle: Graalvm · Mcafee: Web Gateway · F5: Big Ip Local Traffic Manager · Nodejs: Node.js
Configuration A
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.0.0 to 6.2.3 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2 | |
| All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Synology Vs960hd | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 29 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 1.0 | |
| Version 7.2.0 | |
| Version 4.1 | |
| Version 1.0 | |
| Version 14 | |
| Version 3.0.0 | |
| Version 7.3 | |
| Version 1.0 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.7.2.0 to 7.7.2.24 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Related CWEs
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CWE-770
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
References (76)
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.