CVE-2020-9490

Context

This vulnerability is a Deny Of Service (DOS) attack affecting Apache HTTPD servers versions prior to 2.4.46.
By crafting special HTTP headers (Cache-Digest), an attacker could make the vulnerable HTTPD server crash.
 

Consequences

Cyber-terms

Direct impact on the availability of the vulnerable server. The exploitation of the vulnerability does not need authentication of any kind.
 

Managerial-terms

In the case the server hosts an application used by production, the exploitation will lead to direct financial losses by loss of exploitation as the asset will be down and will try to reboot each time the exploit is successful.
 
All websites hosted on the affected machine will be unreachable.
 

Remediation

The only lasting option is updating the Apache HTTP Server to the latest production ready version available. (Version 2.4.54 released on the 06-08-2022)
https://docs.rackspace.com/docs/updating-apache-to-the-latest-version-in-linux 
https://httpd.apache.org/