HTTP/2 Rapid Reset Attack Impacting NGINX Products - Does this affect 3CX?

Status
Not open for further replies.

Michael Menor

Silver Partner
Advanced Certified
Joined
Dec 30, 2016
Messages
83
Reaction score
4
Opened a support case on Wednesday, but still haven't received a response. Anyone else know about this?

Researchers and vendors have disclosed a denial-of-service (DoS) vulnerability in HTTP/2 protocol. The vulnerability (CVE-2023-44487), known as Rapid Reset, has been exploited in the wild in August 2023 through October 2023.

CISA recommends organizations that provide HTTP/2 services apply patches when available and consider configuration changes and other mitigations discussed in the references below. For more information on Rapid Reset, see:
1697211673745.png
 
Quoting the article by nginx:
By relying on the default keepalive limit, NGINX prevents this type of attack.

A standard installation of 3CX on linux does not change "keepalive_requests" or "http2_max_concurrent_streams".

An official response would still be good of course.
 
  • Like
Reactions: Michael Menor
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,078
Members
164,896
Latest member
sameage