CVE-2019-1884: Cisco Web Security Appliance Web Proxy Denial of Service Vulnerability
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in HTTP/HTTPS requests sent through an affected device. A successful attacker could exploit this vulnerability by sending a malicious HTTP/HTTPS request through an affected device. An exploit could allow the attacker to force the device to stop processing traffic, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1884?
CVE-2019-1884 is a vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
How does CVE-2019-1884 impact Cisco AsyncOS Software?
CVE-2019-1884 could cause a denial of service (DoS) condition on an affected device running Cisco AsyncOS Software for Cisco Web Security Appliance.
Which versions of Cisco AsyncOS Software are affected by CVE-2019-1884?
Versions of Cisco AsyncOS Software for Cisco Web Security Appliance between 10.1 and 11.7 are affected by CVE-2019-1884.
What is the severity of CVE-2019-1884?
CVE-2019-1884 has a severity rating of high with a score of 6.5 out of 10.
How can I fix CVE-2019-1884?
To mitigate CVE-2019-1884, Cisco recommends upgrading to a fixed software release based on the information provided in the Cisco Security Advisory.