F5-K000137106: Medium severity F5 BIG-IP Next vulnerability
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. (CVE-2023-44487 also known as HTTP/2 Rapid Reset Attack)
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000137106?
The severity of F5-K000137106 is high due to its potential for denial of service through HTTP/2 rapid reset attacks.
How do I fix F5-K000137106?
To fix F5-K000137106, you should upgrade to the latest version of the affected software with the specified remedies.
What products are affected by F5-K000137106?
F5-K000137106 affects several products including F5 BIG-IP and F5 NGINX, across various versions.
When was F5-K000137106 exploited in the wild?
F5-K000137106 was actively exploited in the wild from August to October 2023.
What type of attack does F5-K000137106 relate to?
F5-K000137106 relates to a denial of service attack caused by rapid request cancellation in the HTTP/2 protocol.