CVE-2013-3385: High severity cisco asyncos vulnerability
The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-602; Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before 7.9.1-102 and 8.0 before 8.0.0-404 allows remote attackers to cause a denial of service (system hang) via a series of (1) HTTP or (2) HTTPS requests to a management interface, aka Bug IDs CSCzv58669, CSCzv63329, and CSCzv78669.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3385?
CVE-2013-3385 is classified as a moderate severity vulnerability.
How do I fix CVE-2013-3385?
To fix CVE-2013-3385, upgrade your Cisco Web Security Appliance or Email Security Appliance to the latest available version.
Which Cisco devices are affected by CVE-2013-3385?
CVE-2013-3385 affects various Cisco devices including IronPort AsyncOS and Email Security Appliances prior to specific version thresholds.
Is there a workaround for CVE-2013-3385?
There are no documented workarounds for CVE-2013-3385; upgrading is recommended.
What are the consequences of not addressing CVE-2013-3385?
Failure to address CVE-2013-3385 could lead to unauthorized access and compromise of the web management interface.