FG-IR-23-397: CVE-2023-44487 - Rapid Reset HTTP/2 vulnerability
The Fortinet Product Security team has evaluated the impact of the vulnerablity HTTP/2 Rapid Reset Attack, listed below:CVE-2023-44487:The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly.https://nvd.nist.gov/vuln/detail/CVE-2023-44487
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-397?
FG-IR-23-397 is rated as a denial of service vulnerability impacting server resource consumption.
How do I fix FG-IR-23-397?
To fix FG-IR-23-397, upgrade FortiOS to version 7.4.2 or later, or FortiProxy to version 7.4.2 or later, depending on your product.
What versions of FortiOS are affected by FG-IR-23-397?
FortiOS versions 7.4.0 to 7.4.1, 7.2.0 to 7.2.7, and 7.0.0 to 7.0.13 are affected by FG-IR-23-397.
What is the impact of FG-IR-23-397?
The impact of FG-IR-23-397 is that it can allow attackers to exploit the HTTP/2 protocol to cause denial of service by quickly resetting multiple streams.
Does FG-IR-23-397 affect FortiProxy?
Yes, FG-IR-23-397 affects FortiProxy versions 7.4.0 to 7.4.1, 7.2.0 to 7.2.7, and all versions of 7.0.