First published: Tue Dec 01 2015(Updated: )
The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer, aka Bug ID CSCut94150.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Web Security Appliance | =8.0.7-142 | |
Cisco Web Security Appliance | =8.5.1-021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6386 has a severity rating classified as high due to its potential to cause denial of service.
To fix CVE-2015-6386, upgrade your Cisco Web Security Appliance to a version beyond 8.0.7-142 and 8.5.1-021.
CVE-2015-6386 affects Cisco Web Security Appliance devices running software versions 8.0.7-142 and 8.5.1-021.
CVE-2015-6386 allows remote attackers to exploit vulnerable FTP sessions to cause excessive CPU consumption leading to denial of service.
Yes, CVE-2015-6386 specifically involves vulnerabilities in the passthrough FTP feature of Cisco Web Security Appliances.