CVE-2019-9515
Last modified
CVE-2019-9515 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. EPSS estimates a 87.81% chance of exploitation in the next 30 days.
Description
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Swiftnio | >= 1.0.0, <= 1.4.0 |
| Apache | Traffic Server | >= 6.0.0, <= 6.2.3 |
| Apache | Traffic Server | >= 7.0.0, <= 7.1.6 |
| Apache | Traffic Server | >= 8.0.0, <= 8.0.3 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.04 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Synology | Skynas | All versions |
| Synology | Diskstation Manager | 6.2 |
| Synology | Vs960hd Firmware | All versions |
| Fedoraproject | Fedora | 29 |
| Fedoraproject | Fedora | 30 |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 15.1 |
| Redhat | Jboss Core Services | 1.0 |
| Redhat | Jboss Enterprise Application Platform | 7.2.0 |
| Redhat | Jboss Enterprise Application Platform | 7.3.0 |
| Redhat | Openshift Container Platform | 4.1 |
| Redhat | Openshift Service Mesh | 1.0 |
| Redhat | Openstack | 14 |
| Redhat | Quay | 3.0.0 |
| Redhat | Single Sign-On | 7.3 |
| Redhat | Software Collections | 1.0 |
| Redhat | Enterprise Linux | 8.0 |
| Oracle | Graalvm | 19.2.0 |
| Mcafee | Web Gateway | >= 7.7.2.0, < 7.7.2.24 |
| Mcafee | Web Gateway | >= 7.8.2.0, < 7.8.2.13 |
| Mcafee | Web Gateway | >= 8.1.0, < 8.2.0 |
| F5 | Big-Ip Local Traffic Manager | >= 11.6.1, < 11.6.5.1 |
| F5 | Big-Ip Local Traffic Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Local Traffic Manager | >= 13.1.0, < 13.1.3.2 |
| F5 | Big-Ip Local Traffic Manager | >= 14.0.0, < 14.0.1.1 |
| F5 | Big-Ip Local Traffic Manager | >= 14.1.0, < 14.1.2.1 |
| F5 | Big-Ip Local Traffic Manager | >= 15.0.0, < 15.0.1.1 |
| Nodejs | Node.Js | >= 8.0.0, <= 8.8.1 |
| Nodejs | Node.Js | >= 8.9.0, < 8.16.1 |
| Nodejs | Node.Js | >= 10.0.0, <= 10.12.0 |
| Nodejs | Node.Js | >= 10.13.0, < 10.16.3 |
| Nodejs | Node.Js | >= 12.0.0, < 12.8.1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/16Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2861Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4018Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4019Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4021Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4042Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4045Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Third Party Advisory
- https://kb.cert.org/vuls/id/605641/Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/24Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/43Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/18Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0005/Third Party Advisory
- https://support.f5.com/csp/article/K50233772Third Party Advisory
- https://usn.ubuntu.com/4308-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4508Third Party Advisory
- https://www.debian.org/security/2019/dsa-4520Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_33Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/16Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2861Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4018Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4019Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4021Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4042Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4045Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Third Party Advisory
- https://kb.cert.org/vuls/id/605641/Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/24Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/43Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/18Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0005/Third Party Advisory
- https://support.f5.com/csp/article/K50233772Third Party Advisory
- https://usn.ubuntu.com/4308-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4508Third Party Advisory
- https://www.debian.org/security/2019/dsa-4520Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_33Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9515?
How severe is CVE-2019-9515?
How do I fix CVE-2019-9515?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-9509The web interface of the Vertiv Avocent UMG-4000 version 4.2…5.4
- CVE-2019-9510A vulnerability in Microsoft Windows 10 1803 and Windows Ser…7.8
- CVE-2019-9511Some HTTP/2 implementations are vulnerable to window size ma…7.5
- CVE-2019-9512Some HTTP/2 implementations are vulnerable to ping floods, p…7.5
- CVE-2019-9513Some HTTP/2 implementations are vulnerable to resource loops…7.5
- CVE-2019-9514Some HTTP/2 implementations are vulnerable to a reset flood,…7.5
- CVE-2019-9516Some HTTP/2 implementations are vulnerable to a header leak,…6.5
- CVE-2019-9517Some HTTP/2 implementations are vulnerable to unconstrained …7.5
- CVE-2019-9518Some HTTP/2 implementations are vulnerable to a flood of emp…7.5
- CVE-2019-9529The web application portal of the Cobham EXPLORER 710, firmw…5.5
- CVE-2019-9530The web root directory of the Cobham EXPLORER 710, firmware …5.5
- CVE-2019-9531The web application portal of the Cobham EXPLORER 710, firmw…9.8
Are you affected by CVE-2019-9515?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
