CVE-2016-1296: High severity cisco web security appliance vulnerability
The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1296?
CVE-2016-1296 has a high severity rating due to its potential for remote exploitation.
How do I fix CVE-2016-1296?
To fix CVE-2016-1296, you should upgrade your Cisco Web Security Appliance to a version that is not affected by this vulnerability.
What types of devices are affected by CVE-2016-1296?
CVE-2016-1296 affects Cisco Web Security Appliance devices running specific versions including 8.5.3-055, 9.1.0-000, and 9.5.0-235.
Can CVE-2016-1296 be exploited remotely?
Yes, CVE-2016-1296 can be exploited remotely by attackers using a malformed HTTP method to bypass proxy restrictions.
What is the impact of CVE-2016-1296?
The impact of CVE-2016-1296 includes the ability for remote attackers to bypass intended proxy restrictions on affected devices.