CVE-2015-0628: Infoleak
Published Feb 20, 2015
·Updated
The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP method, aka Bug ID CSCus79174.
Affected Software
1 affected component
Cisco Web Security Appliance
Event History
Feb 20, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0628?
CVE-2015-0628 is considered a medium severity vulnerability that allows remote attackers to bypass proxying restrictions.
2
How do I fix CVE-2015-0628?
To fix CVE-2015-0628, users should update their Cisco Web Security Appliance to the latest software version provided by Cisco.
3
What devices are affected by CVE-2015-0628?
CVE-2015-0628 affects Cisco Web Security Appliance devices.
4
Can CVE-2015-0628 be exploited remotely?
Yes, CVE-2015-0628 can be exploited remotely by attackers through malformed HTTP methods.
5
What are the potential impacts of CVE-2015-0628?
The potential impacts of CVE-2015-0628 include unauthorized access to resources that should be restricted by proxy settings.