First published: Wed May 25 2016(Updated: )
Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Web Security Appliance | ||
Cisco Web Security Appliance | =8.5.0-497 | |
Cisco Web Security Appliance | =8.5.0.000 | |
Cisco Web Security Appliance | =8.5.1-021 | |
Cisco Web Security Appliance | =8.5.2-024 | |
Cisco Web Security Appliance | =8.5.2-027 | |
Cisco Web Security Appliance | =8.5.3-055 | |
Cisco Web Security Appliance | =9.0.0-193 | |
Cisco Web Security Appliance | =9.0_base | |
Cisco Web Security Appliance | =9.1.0-000 | |
Cisco Web Security Appliance | =9.1_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1381 is classified as a high severity vulnerability due to its potential to cause denial of service through memory consumption.
To resolve CVE-2016-1381, users should upgrade to Cisco AsyncOS version 9.0.1-162 or later that addresses the memory leak issue.
CVE-2016-1381 affects Cisco Web Security Appliance devices running AsyncOS versions 8.5 through 9.0 before 9.0.1-162.
CVE-2016-1381 allows remote attackers to exploit the vulnerability by sending HTTP file-range requests, leading to denial of service.
There are no known workarounds for CVE-2016-1381, so updating the software is the recommended action.