First published: Thu Mar 03 2016(Updated: )
The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Web Security Appliance | =9.0.0-193 | |
Cisco Web Security Appliance | =8.5.0-497 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1288 has a moderate severity rating as it can cause a denial of service on affected Cisco Web Security Appliance devices.
To fix CVE-2016-1288, upgrade the Cisco Web Security Appliance software to a version that is not affected, such as AsyncOS 8.5.3-051 or later and 9.0.0-485 or later.
CVE-2016-1288 affects users of Cisco Web Security Appliance devices running AsyncOS versions prior to 8.5.3-051 and 9.x before 9.0.0-485.
CVE-2016-1288 is a denial-of-service vulnerability that can be exploited by sending malformed HTTPS requests.
Yes, CVE-2016-1288 can be exploited remotely by attackers leveraging certain intranet connectivity.