PT-2016-3712 · Cisco · Waas+1

Published

2016-01-27

·

Updated

2016-12-07

·

CVE-2015-6421

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) versions 5.x before 5.3.5d Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) version 5.4 Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) versions 5.5 before 5.5.3
Description The issue affects the CIFS optimization functionality due to the cifs-ao component. It allows remote attackers to cause a denial of service, resulting in resource consumption and device reload, via crafted network traffic.
Recommendations For versions 5.x before 5.3.5d, update to version 5.3.5d or later. For version 5.4, update to version 5.5.3 or later. For versions 5.5 before 5.5.3, update to version 5.5.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6421

Affected Products

Waas
Vwaas