CVE-2019-9515
Last modified
CVE-2019-9515 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. EPSS estimates a 87.81% chance of exploitation in the next 30 days.
Description
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Swiftnio | >= 1.0.0, <= 1.4.0 |
| Apache | Traffic Server | >= 6.0.0, <= 6.2.3 |
| Apache | Traffic Server | >= 7.0.0, <= 7.1.6 |
| Apache | Traffic Server | >= 8.0.0, <= 8.0.3 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.04 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Synology | Skynas | All versions |
| Synology | Diskstation Manager | 6.2 |
| Synology | Vs960hd Firmware | All versions |
| Fedoraproject | Fedora | 29 |
| Fedoraproject | Fedora | 30 |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 15.1 |
| Redhat | Jboss Core Services | 1.0 |
| Redhat | Jboss Enterprise Application Platform | 7.2.0 |
| Redhat | Jboss Enterprise Application Platform | 7.3.0 |
| Redhat | Openshift Container Platform | 4.1 |
| Redhat | Openshift Service Mesh | 1.0 |
| Redhat | Openstack | 14 |
| Redhat | Quay | 3.0.0 |
| Redhat | Single Sign-On | 7.3 |
| Redhat | Software Collections | 1.0 |
| Redhat | Enterprise Linux | 8.0 |
| Oracle | Graalvm | 19.2.0 |
| Mcafee | Web Gateway | >= 7.7.2.0, < 7.7.2.24 |
| Mcafee | Web Gateway | >= 7.8.2.0, < 7.8.2.13 |
| Mcafee | Web Gateway | >= 8.1.0, < 8.2.0 |
| F5 | Big-Ip Local Traffic Manager | >= 11.6.1, < 11.6.5.1 |
| F5 | Big-Ip Local Traffic Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Local Traffic Manager | >= 13.1.0, < 13.1.3.2 |
| F5 | Big-Ip Local Traffic Manager | >= 14.0.0, < 14.0.1.1 |
| F5 | Big-Ip Local Traffic Manager | >= 14.1.0, < 14.1.2.1 |
| F5 | Big-Ip Local Traffic Manager | >= 15.0.0, < 15.0.1.1 |
| Nodejs | Node.Js | >= 8.0.0, <= 8.8.1 |
| Nodejs | Node.Js | >= 8.9.0, < 8.16.1 |
| Nodejs | Node.Js | >= 10.0.0, <= 10.12.0 |
| Nodejs | Node.Js | >= 10.13.0, < 10.16.3 |
| Nodejs | Node.Js | >= 12.0.0, < 12.8.1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/16Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2861Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4018Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4019Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4021Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4042Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4045Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Third Party Advisory
- https://kb.cert.org/vuls/id/605641/Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/24Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/43Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/18Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0005/Third Party Advisory
- https://support.f5.com/csp/article/K50233772Third Party Advisory
- https://usn.ubuntu.com/4308-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4508Third Party Advisory
- https://www.debian.org/security/2019/dsa-4520Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_33Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/16Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2861Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4018Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4019Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4021Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4042Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4045Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Third Party Advisory
- https://kb.cert.org/vuls/id/605641/Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/24Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/43Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/18Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190823-0005/Third Party Advisory
- https://support.f5.com/csp/article/K50233772Third Party Advisory
- https://usn.ubuntu.com/4308-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4508Third Party Advisory
- https://www.debian.org/security/2019/dsa-4520Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_33Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9515?
How severe is CVE-2019-9515?
How do I fix CVE-2019-9515?
Are you affected by CVE-2019-9515?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
