CVE-2016-1381: High severity cisco web security appliance vulnerability
Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1381?
CVE-2016-1381 is classified as a high severity vulnerability due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2016-1381?
To resolve CVE-2016-1381, users should upgrade to Cisco AsyncOS version 9.0.1-162 or later that addresses the memory leak issue.
What devices are affected by CVE-2016-1381?
CVE-2016-1381 affects Cisco Web Security Appliance devices running AsyncOS versions 8.5 through 9.0 before 9.0.1-162.
What kind of attack does CVE-2016-1381 enable?
CVE-2016-1381 allows remote attackers to exploit the vulnerability by sending HTTP file-range requests, leading to denial of service.
Is there a workaround for CVE-2016-1381?
There are no known workarounds for CVE-2016-1381, so updating the software is the recommended action.