CVE-2016-6416: Buffer Overflow
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz86065.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6416?
CVE-2016-6416 has been rated as High severity due to its potential to cause a denial of service.
How do I fix CVE-2016-6416?
To fix CVE-2016-6416, upgrade your Cisco devices to the patched versions specified by Cisco.
What devices are affected by CVE-2016-6416?
CVE-2016-6416 affects Cisco AsyncOS on Email Security Appliance, Web Security Appliance, and Content Security Management Appliance versions 9.6.0-000 through 9.9.6-026.
What type of attack does CVE-2016-6416 facilitate?
CVE-2016-6416 enables remote attackers to launch a denial of service attack through an FTP flood.
Is there a workaround for CVE-2016-6416?
Cisco recommends upgrading to an unaffected version as the primary solution for CVE-2016-6416, as there is no effective workaround.