CVE-2016-1288: Input Validation
The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1288?
CVE-2016-1288 has a moderate severity rating as it can cause a denial of service on affected Cisco Web Security Appliance devices.
How do I fix CVE-2016-1288?
To fix CVE-2016-1288, upgrade the Cisco Web Security Appliance software to a version that is not affected, such as AsyncOS 8.5.3-051 or later and 9.0.0-485 or later.
Who is affected by CVE-2016-1288?
CVE-2016-1288 affects users of Cisco Web Security Appliance devices running AsyncOS versions prior to 8.5.3-051 and 9.x before 9.0.0-485.
What type of vulnerability is CVE-2016-1288?
CVE-2016-1288 is a denial-of-service vulnerability that can be exploited by sending malformed HTTPS requests.
Can CVE-2016-1288 be exploited remotely?
Yes, CVE-2016-1288 can be exploited remotely by attackers leveraging certain intranet connectivity.