← Back

CVE-2019-9515

nvd nist
Published: Aug 13, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Affected (41)

Show all products
1 product
Swiftnio
1 product
Traffic Server
1 product
Ubuntu Linux
1 product
Debian Linux
3 products
Diskstation Manager
Skynas
Vs960hd Firmware
1 product
Fedora
1 product
Leap
9 products
Enterprise Linux
Jboss Core Services
Openshift Container Platform
Openshift Service Mesh
Openstack
Quay
Single Sign On
Software Collections
1 product
Graalvm
1 product
Web Gateway
1 product
Big Ip Local Traffic Manager
1 product
Node.js
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.4.0
Running on/withPlatform Versions
Apple
Mac Os X
From 10.12
Canonical
Ubuntu Linux
From 14.04
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 6.0.0 to 6.2.3
From 7.0.0 to 7.1.6
From 8.0.0 to 8.0.3
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 18.04
Version 19.04
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.2
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Synology
Vs960hd
All versions
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 29
Version 30
Configuration H
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.1
Configuration I
10 vulnerable
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 19.2.0
Configuration K
3 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
From 7.7.2.0 to 7.7.2.24
From 7.8.2.0 to 7.8.2.13
From 8.1.0 to 8.2.0
Configuration L
6 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.6.1 to 11.6.5.1
From 12.1.0 to 12.1.5.1
From 13.1.0 to 13.1.3.2
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.2.1
From 15.0.0 to 15.0.1.1
Configuration M
5 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 10.0.0 to 10.12.0
From 12.0.0 to 12.8.1
From 8.0.0 to 8.8.1
From 10.13.0 to 10.16.3
From 8.9.0 to 8.16.1

References (76)

Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.