Is the H2 protocol enabled on the FTD 4120 appliance? If so, how can it be configured?
I have been notified on our vulnerability scan the below.
Vulnerability Name:
Apache HTTPD: DoS for HTTP/2 connections by continuous SETTINGS (CVE-2018-11763)
Description of findings:
By sending continous SETTINGS frames of maximum size an ongoing HTTP/2 connection could be kept busy and would never time out. This can be abused for a DoS on the server. This only affect a server that has enabled the h2 protocol.
Thanks!
Chris