QID 731034

Date Published: 2023-12-18

QID 731034: Cisco Prime Infrastructure Distributed Denial of Service (DDoS) Vulnerability (cisco-sa-http2-reset-d8Kf32vZ)

Cisco Prime Infrastructure is vulnerable to HTTP/2 Rapid Reset Attack

Affected Versions:
Cisco Prime Infrastructure prior to version 3.10.4

QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable Cisco Prime Infrastructure version retrieved via a GET request to a "webacs/js/xmp/nls/xmp.js"

Successful exploitation could allow distributed denial of service (DDoS) attack

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-http2-reset-d8Kf32vZ for more information.

    CVEs related to QID 731034

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-http2-reset-d8Kf32vZ URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ