PT-2016-3712 · Cisco · Waas+1
Published
2016-01-27
·
Updated
2016-12-07
·
CVE-2015-6421
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) versions 5.x before 5.3.5d
Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) version 5.4
Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) versions 5.5 before 5.5.3
Description
The issue affects the CIFS optimization functionality due to the cifs-ao component. It allows remote attackers to cause a denial of service, resulting in resource consumption and device reload, via crafted network traffic.
Recommendations
For versions 5.x before 5.3.5d, update to version 5.3.5d or later.
For version 5.4, update to version 5.5.3 or later.
For versions 5.5 before 5.5.3, update to version 5.5.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Waas
Vwaas