CVE-2016-1383: High severity cisco web security appliance vulnerability
Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1383?
CVE-2016-1383 is classified as a denial of service vulnerability due to memory consumption issues.
How do I fix CVE-2016-1383?
To mitigate CVE-2016-1383, users should upgrade to a fixed version of Cisco AsyncOS that addresses this memory leak.
Which Cisco devices are affected by CVE-2016-1383?
CVE-2016-1383 affects Cisco Web Security Appliance devices running vulnerable versions of AsyncOS up to 8.8.
How can CVE-2016-1383 be exploited?
CVE-2016-1383 can be exploited remotely by sending an unspecified HTTP status code, leading to a denial of service.
Is there a workaround for CVE-2016-1383?
Currently, there are no specific workarounds for CVE-2016-1383; updating to the latest version is recommended.