CVE Vulnerabilities

CVE-2016-6407

Published: Sep 17, 2016 | Modified: Jul 30, 2017
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219.

Affected Software

Name Vendor Start Version End Version
Web_security_appliance Cisco 5.6.0-623 5.6.0-623
Web_security_appliance Cisco 6.0.0-000 6.0.0-000
Web_security_appliance Cisco 7.1.0 7.1.0
Web_security_appliance Cisco 7.1.1 7.1.1
Web_security_appliance Cisco 7.1.2 7.1.2
Web_security_appliance Cisco 7.1.3 7.1.3
Web_security_appliance Cisco 7.1.4 7.1.4
Web_security_appliance Cisco 7.5.0-000 7.5.0-000
Web_security_appliance Cisco 7.5.0-825 7.5.0-825
Web_security_appliance Cisco 7.5.1-000 7.5.1-000
Web_security_appliance Cisco 7.5.2-000 7.5.2-000
Web_security_appliance Cisco 7.5.2-hp2-303 7.5.2-hp2-303
Web_security_appliance Cisco 7.7.0-000 7.7.0-000
Web_security_appliance Cisco 7.7.0-608 7.7.0-608
Web_security_appliance Cisco 7.7.1-000 7.7.1-000
Web_security_appliance Cisco 7.7.5-835 7.7.5-835
Web_security_appliance Cisco 8.0.0-000 8.0.0-000
Web_security_appliance Cisco 8.0.5 8.0.5
Web_security_appliance Cisco 8.0.6 8.0.6
Web_security_appliance Cisco 8.0.6-078 8.0.6-078
Web_security_appliance Cisco 8.0.6-119 8.0.6-119
Web_security_appliance Cisco 8.0.7 8.0.7
Web_security_appliance Cisco 8.0.7-142 8.0.7-142
Web_security_appliance Cisco 8.0.8-mr-113 8.0.8-mr-113
Web_security_appliance Cisco 8.5.0-497 8.5.0-497
Web_security_appliance Cisco 8.5.0.000 8.5.0.000
Web_security_appliance Cisco 8.5.1-021 8.5.1-021
Web_security_appliance Cisco 8.5.2-024 8.5.2-024
Web_security_appliance Cisco 8.5.2-027 8.5.2-027
Web_security_appliance Cisco 8.5.3-055 8.5.3-055
Web_security_appliance Cisco 8.8.0-000 8.8.0-000
Web_security_appliance Cisco 8.8.0-085 8.8.0-085
Web_security_appliance Cisco 9.0.0-193 9.0.0-193
Web_security_appliance Cisco 9.0_base 9.0_base
Web_security_appliance Cisco 9.1.0-000 9.1.0-000
Web_security_appliance Cisco 9.1.0-070 9.1.0-070
Web_security_appliance Cisco 9.1_base 9.1_base
Web_security_appliance Cisco 9.5.0-235 9.5.0-235
Web_security_appliance Cisco 9.5.0-284 9.5.0-284
Web_security_appliance Cisco 9.5.0-444 9.5.0-444
Web_security_appliance Cisco 9.5_base 9.5_base

References