PT-2021-4662 · Cisco · Cisco Asyncos+1

Published

2021-10-06

·

Updated

2021-10-14

·

CVE-2021-34698

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Web Security Appliance (WSA) versions not specified
Description A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This issue is due to improper memory management in the proxy service. An attacker could exploit this by establishing a large number of HTTPS connections to the affected device, potentially causing the system to stop processing new connections. Manual intervention may be required to recover from this situation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05355
CVE-2021-34698

Affected Products

Cisco Asyncos
Cisco Web Security Appliance