First published: Wed May 25 2016(Updated: )
Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Web Security Appliance | ||
Cisco Web Security Appliance | =8.0.0-000 | |
Cisco Web Security Appliance | =8.0.5 | |
Cisco Web Security Appliance | =8.0.6 | |
Cisco Web Security Appliance | =8.0.6-078 | |
Cisco Web Security Appliance | =8.0.6-119 | |
Cisco Web Security Appliance | =8.0.7 | |
Cisco Web Security Appliance | =8.0.7-142 | |
Cisco Web Security Appliance | =8.0.8-mr-113 | |
Cisco Web Security Appliance | =8.5.0-000 | |
Cisco Web Security Appliance | =8.5.0-497 | |
Cisco Web Security Appliance | =8.5.1-021 | |
Cisco Web Security Appliance | =8.5.2-024 | |
Cisco Web Security Appliance | =8.5.2-027 | |
Cisco Web Security Appliance | =8.5.3-055 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1380 has been classified as a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2016-1380, upgrade to Cisco AsyncOS version 8.0.6-119 or later.
CVE-2016-1380 affects Cisco Web Security Appliance devices running versions prior to 8.0.6-119.
Yes, CVE-2016-1380 can be exploited remotely using a crafted HTTP POST request.
The impact of CVE-2016-1380 is that it could result in a denial of service through a proxy-process hang.