www.belgium.be Logo of the federal government

Warning: New DDoS technique Rapid Reset Attack uses actively exploited zero-day in HTTP/2 - CVE-2023-44487

Referentie: 
Advisory #2023-122
Versie: 
2.0
Geïmpacteerde software: 
HTTP/2
Type: 
Denial of Service
CVE/CVSS: 
CVE-2023-44487 
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Bronnen

Risico’s

Risk: A new DDoS technique named 'HTTP/2 Rapid Reset' has been actively exploited as a zero-day vulnerability since August, breaking all previous DDoS records. It exploits a zero-day vulnerability tracked as CVE-2023-44487, abusing a weakness in the HTTP/2 protocol.
Threat Actors: Threat actors, including those with relatively small botnets, have already abused this technique. As more expansive botnets adopt this method, it is expected to continue breaking records.
Historical Events: Since late August, Cloudflare, Google and Amazon Web Services have detected and mitigated thousands of 'HTTP/2 Rapid Reset' DDoS attacks, several of which breaking previous DDoS records.
Technology Targeted: This vulnerability targets the HTTP/2 protocol, commonly used in web servers and browsers.
Interest to Actors: Threat actors can overwhelm target servers/applications, imposing a Denial of Service (DoS) state, making it appealing for those with malicious intent.
Impact on CIA Triad: There is a high impact on availability.

Beschrijving

A new DDoS technique called 'HTTP/2 Rapid Reset' is currently being exploited as a zero-day vulnerability. This method abuses a zero-day vulnerability, CVE-2023-44487, which targets a weakness in the HTTP/2 protocol. In simple terms, it overwhelms target servers or applications by exploiting HTTP/2's stream cancellation feature. This feature, can be abused by malicious actors to send a barrage of HTTP/2 requests and resets, causing rapid resets and overwhelming the server's capacity to respond to new incoming requests.

Several major tech companies, including Amazon Web Services, Cloudflare, and Google, have reported mitigating record-breaking DDoS attacks using this technique.

Aanbevolen acties

The Centre for Cyber Security Belgium strongly recommends to take the following actions:

  1. Implement DDoS protection: Organisations should employ multifaceted DDoS protection methods to mitigate the risk of 'HTTP/2 Rapid Reset' attacks.
  2. Keep Software Updated: Ensure that all software utilizing the HTTP/2 protocol is up to date. Developers should implement rate controls to mitigate HTTP/2 Rapid Reset attacks effectively.
  3. Stay Informed: Monitor for security advisories and updates related to this vulnerability. Ensure that your security teams are informed and ready to respond to any potential threats.
  4. Incident Response Plan: Develop and regularly update an incident response plan that includes specific actions for mitigating DDoS attacks. Ensure that your organisation's response plan is tested and ready for implementation. Also look at "How To Protect Your Organisation Against a DDoS Attack":

Possible workaround

  • Disable the HTTP/2 protocol

Vendor advisories and statements

Referenties