PT-2016-4749 · Cisco · Cisco Web Security Appliance
Published
2016-05-25
·
Updated
2016-12-01
·
CVE-2016-1382
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Web Security Appliance (WSA) versions prior to 8.5.3-069
Cisco Web Security Appliance (WSA) versions 8.6 through 8.8
Description
The issue is related to the mishandling of memory allocation for HTTP requests. This allows remote attackers to cause a denial of service, resulting in a proxy-process reload, via a crafted request.
Recommendations
For versions prior to 8.5.3-069, update to version 8.5.3-069 or later.
For versions 8.6 through 8.8, update to a version outside of this range, as no specific fixed version within the range is provided.
As a temporary workaround, consider restricting access to the HTTP request handling component to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Web Security Appliance