CVE-2016-1440: Medium severity cisco web security appliance vulnerability
The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote attackers to cause a denial of service (CPU consumption) by establishing an FTP session and then improperly terminating the control connection after a file transfer, aka Bug ID CSCuy43468.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1440?
CVE-2016-1440 has a high severity due to the potential for denial of service caused by high CPU consumption.
How do I fix CVE-2016-1440?
To fix CVE-2016-1440, upgrade your Cisco Web Security Appliance to a version that is not affected by the vulnerability.
What types of attacks exploit CVE-2016-1440?
CVE-2016-1440 can be exploited by remote attackers who establish an FTP session and improperly terminate the control connection.
Which Cisco Web Security Appliance versions are vulnerable to CVE-2016-1440?
Versions of Cisco Web Security Appliance up to and including 9.1.0-070 are vulnerable to CVE-2016-1440.
What impact can CVE-2016-1440 have on a network?
CVE-2016-1440 can potentially cause significant strain on CPU resources, leading to degraded performance or unavailability of the Cisco Web Security Appliance.