CVE-2013-5537: Input Validation
The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does not properly manage the state of HTTP and HTTPS sessions, which allows remote attackers to cause a denial of service (management GUI outage) via multiple TCP connections, aka Bug IDs CSCuj59411, CSCuf89818, and CSCuh05635.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5537?
CVE-2013-5537 is categorized as a denial of service vulnerability that can cause outages in the management GUI.
How do I fix CVE-2013-5537?
To mitigate CVE-2013-5537, update your Cisco Web Security Appliance, Email Security Appliance, or Content Security Management Appliance to the latest available firmware version.
Which devices are affected by CVE-2013-5537?
CVE-2013-5537 affects Cisco Web Security Appliance, Cisco Email Security Appliance, and Cisco Content Security Management Appliance devices.
What impact does CVE-2013-5537 have on systems?
CVE-2013-5537 can allow remote attackers to trigger a denial of service, leading to potential management GUI outages.
Is there a workaround for CVE-2013-5537?
There are no official workarounds for CVE-2013-5537, and the recommended action is to apply the available firmware updates.