V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2019-9512
DEB
High

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings t…

CVSS
7.5
High
EPSS
0.51
p97
Published
2019-01-01
Updated
2019-01-01
Description

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Tags · CWE
Pre-auth
CWE-400
CAPEC-147
CAPEC-227
CAPEC-492
Affected products
Ansible-operatorAnsible-service-brokerAnsible-service-brokerApbApbApbAtomic-enterprise-service-catalogAtomic-enterprise-service-catalogAtomic-openshiftAtomic-openshiftAtomic-openshiftAtomic-openshift-cluster-autoscalerAtomic-openshift-deschedulerAtomic-openshift-deschedulerAtomic-openshift-dockerregistryAtomic-openshift-metrics-serverAtomic-openshift-node-problem-detectorAtomic-openshift-node-problem-detectorAtomic-openshift-service-idlerAtomic-openshift-web-console
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.508 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
ansible-operatorTracked
ansible-service-brokerTracked
ansible-service-brokerTracked
apbTracked
apbTracked
apbTracked
atomic-enterprise-service-catalogTracked
atomic-enterprise-service-catalogTracked
atomic-openshiftTracked
atomic-openshiftTracked
atomic-openshiftTracked
atomic-openshift-cluster-autoscalerTracked
atomic-openshift-deschedulerTracked
atomic-openshift-deschedulerTracked
atomic-openshift-dockerregistryTracked
atomic-openshift-metrics-serverTracked
atomic-openshift-node-problem-detectorTracked
atomic-openshift-node-problem-detectorTracked
atomic-openshift-service-idlerTracked
atomic-openshift-web-consoleTracked
Source databases
DEB
MSR
CVE
RED
UBU
Related vulnerabilities