CVE-2016-6407: High severity cisco web security appliance vulnerability
Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6407?
CVE-2016-6407 has been rated as a high severity vulnerability due to its potential to cause denial of service via link saturation.
How do I fix CVE-2016-6407?
To fix CVE-2016-6407, it is recommended to upgrade your Cisco Web Security Appliance to a version that addresses this vulnerability.
Which Cisco products are affected by CVE-2016-6407?
CVE-2016-6407 affects multiple versions of Cisco Web Security Appliance, specifically AsyncOS versions up to 9.5.0-444.
Can CVE-2016-6407 be exploited remotely?
Yes, CVE-2016-6407 can be exploited remotely by attackers making numerous HTTP requests for overlapping byte ranges.
What type of attack does CVE-2016-6407 facilitate?
CVE-2016-6407 facilitates denial of service attacks by overwhelming the device with excessive HTTP requests.