PT-2016-4749 · Cisco · Cisco Web Security Appliance

Published

2016-05-25

·

Updated

2016-12-01

·

CVE-2016-1382

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Web Security Appliance (WSA) versions prior to 8.5.3-069 Cisco Web Security Appliance (WSA) versions 8.6 through 8.8
Description The issue is related to the mishandling of memory allocation for HTTP requests. This allows remote attackers to cause a denial of service, resulting in a proxy-process reload, via a crafted request.
Recommendations For versions prior to 8.5.3-069, update to version 8.5.3-069 or later. For versions 8.6 through 8.8, update to a version outside of this range, as no specific fixed version within the range is provided. As a temporary workaround, consider restricting access to the HTTP request handling component to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1382

Affected Products

Cisco Web Security Appliance