CVE-2016-6360: Input Validation
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6360?
CVE-2016-6360 has been classified with a medium severity due to its potential for causing partial denial of service conditions.
How do I fix CVE-2016-6360?
To fix CVE-2016-6360, it is recommended to upgrade to the latest firmware version provided by Cisco for the affected Email Security Appliances and Web Security Appliances.
Which products are affected by CVE-2016-6360?
CVE-2016-6360 affects specific versions of Cisco's Email Security Appliance and Web Security Appliance.
Can CVE-2016-6360 be exploited remotely?
Yes, CVE-2016-6360 can be exploited by an unauthenticated remote attacker.
What are the consequences of not patching CVE-2016-6360?
Failure to patch CVE-2016-6360 may lead to frequent AMP process restarts, resulting in service disruption and a potential denial of service.