CVE-2016-9212: Input Validation
A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to connect to a secure website over Secure Sockets Layer (SSL) or Transport Layer Security (TLS), even if the WSA is configured to block connections to the website. Affected Products: This vulnerability affects Cisco Web Security Appliances if the HTTPS decryption options are enabled and configured for the device to block connections to certain websites. More Information: CSCvb49012. Known Affected Releases: 9.0.1-162 9.1.1-074.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9212?
CVE-2016-9212 is classified as a medium severity vulnerability.
How do I fix CVE-2016-9212?
To remediate CVE-2016-9212, update your Cisco Web Security Appliance to a fixed version as specified in Cisco's security advisory.
What types of attacks can CVE-2016-9212 allow?
CVE-2016-9212 can allow unauthenticated remote attackers to connect to secure websites using SSL or TLS.
Which Cisco Web Security Appliance versions are affected by CVE-2016-9212?
The affected versions of Cisco Web Security Appliance are 9.0.1-162 and 9.1.1-074.
Is authentication required to exploit CVE-2016-9212?
No, CVE-2016-9212 can be exploited by unauthenticated attackers.