First published: Wed Jan 20 2016(Updated: )
The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Web Security Appliance | =8.5.3-055 | |
Cisco Web Security Appliance | =9.1.0-000 | |
Cisco Web Security Appliance | =9.5.0-235 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1296 has a high severity rating due to its potential for remote exploitation.
To fix CVE-2016-1296, you should upgrade your Cisco Web Security Appliance to a version that is not affected by this vulnerability.
CVE-2016-1296 affects Cisco Web Security Appliance devices running specific versions including 8.5.3-055, 9.1.0-000, and 9.5.0-235.
Yes, CVE-2016-1296 can be exploited remotely by attackers using a malformed HTTP method to bypass proxy restrictions.
The impact of CVE-2016-1296 includes the ability for remote attackers to bypass intended proxy restrictions on affected devices.