CVE-2016-1380: Input Validation
Published May 25, 2016
·Updated
Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171.
Affected Software
15 affected components
Cisco Web Security Appliance
Cisco Web Security Appliance=8.0.0-000
Cisco Web Security Appliance=8.0.5
Cisco Web Security Appliance=8.0.6
Cisco Web Security Appliance=8.0.6-078
Cisco Web Security Appliance=8.0.6-119
Cisco Web Security Appliance=8.0.7
Cisco Web Security Appliance=8.0.7-142
Cisco Web Security Appliance=8.0.8-mr-113
Cisco Web Security Appliance=8.5.0-000
Cisco Web Security Appliance=8.5.0-497
Cisco Web Security Appliance=8.5.1-021
Cisco Web Security Appliance=8.5.2-024
Cisco Web Security Appliance=8.5.2-027
Cisco Web Security Appliance=8.5.3-055
Event History
May 25, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1380?
CVE-2016-1380 has been classified as a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2016-1380?
To fix CVE-2016-1380, upgrade to Cisco AsyncOS version 8.0.6-119 or later.
3
What devices are affected by CVE-2016-1380?
CVE-2016-1380 affects Cisco Web Security Appliance devices running versions prior to 8.0.6-119.
4
Can CVE-2016-1380 be exploited remotely?
Yes, CVE-2016-1380 can be exploited remotely using a crafted HTTP POST request.
5
What is the impact of CVE-2016-1380?
The impact of CVE-2016-1380 is that it could result in a denial of service through a proxy-process hang.