CVE-2015-6293: High severity cisco web security appliance vulnerability
Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple file-range requests, aka Bug ID CSCur39155.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6293?
CVE-2015-6293 has been classified as a denial of service vulnerability.
How do I fix CVE-2015-6293?
To fix CVE-2015-6293, upgrade your Cisco Web Security Appliance to the latest version as advised in the security advisory.
What are the affected versions for CVE-2015-6293?
CVE-2015-6293 affects Cisco AsyncOS versions prior to 8.0.8-113, 8.1.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085.
Can CVE-2015-6293 be exploited remotely?
Yes, CVE-2015-6293 can be exploited remotely by attackers through multiple file-range requests.
What kind of impact does CVE-2015-6293 have on the system?
The impact of CVE-2015-6293 is memory consumption that leads to denial of service on affected systems.