CVE Vulnerabilities

CVE-2016-6407

Published: Sep 17, 2016 | Modified: Jul 30, 2017
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219.

Affected Software

Name Vendor Start Version End Version
Web_security_appliance Cisco 5.6.0-623 (including) 5.6.0-623 (including)
Web_security_appliance Cisco 6.0.0-000 (including) 6.0.0-000 (including)
Web_security_appliance Cisco 7.1.0 (including) 7.1.0 (including)
Web_security_appliance Cisco 7.1.1 (including) 7.1.1 (including)
Web_security_appliance Cisco 7.1.2 (including) 7.1.2 (including)
Web_security_appliance Cisco 7.1.3 (including) 7.1.3 (including)
Web_security_appliance Cisco 7.1.4 (including) 7.1.4 (including)
Web_security_appliance Cisco 7.5.0-000 (including) 7.5.0-000 (including)
Web_security_appliance Cisco 7.5.0-825 (including) 7.5.0-825 (including)
Web_security_appliance Cisco 7.5.1-000 (including) 7.5.1-000 (including)
Web_security_appliance Cisco 7.5.2-000 (including) 7.5.2-000 (including)
Web_security_appliance Cisco 7.5.2-hp2-303 (including) 7.5.2-hp2-303 (including)
Web_security_appliance Cisco 7.7.0-000 (including) 7.7.0-000 (including)
Web_security_appliance Cisco 7.7.0-608 (including) 7.7.0-608 (including)
Web_security_appliance Cisco 7.7.1-000 (including) 7.7.1-000 (including)
Web_security_appliance Cisco 7.7.5-835 (including) 7.7.5-835 (including)
Web_security_appliance Cisco 8.0.0-000 (including) 8.0.0-000 (including)
Web_security_appliance Cisco 8.0.5 (including) 8.0.5 (including)
Web_security_appliance Cisco 8.0.6 (including) 8.0.6 (including)
Web_security_appliance Cisco 8.0.6-078 (including) 8.0.6-078 (including)
Web_security_appliance Cisco 8.0.6-119 (including) 8.0.6-119 (including)
Web_security_appliance Cisco 8.0.7 (including) 8.0.7 (including)
Web_security_appliance Cisco 8.0.7-142 (including) 8.0.7-142 (including)
Web_security_appliance Cisco 8.0.8-mr-113 (including) 8.0.8-mr-113 (including)
Web_security_appliance Cisco 8.5.0-497 (including) 8.5.0-497 (including)
Web_security_appliance Cisco 8.5.0.000 (including) 8.5.0.000 (including)
Web_security_appliance Cisco 8.5.1-021 (including) 8.5.1-021 (including)
Web_security_appliance Cisco 8.5.2-024 (including) 8.5.2-024 (including)
Web_security_appliance Cisco 8.5.2-027 (including) 8.5.2-027 (including)
Web_security_appliance Cisco 8.5.3-055 (including) 8.5.3-055 (including)
Web_security_appliance Cisco 8.8.0-000 (including) 8.8.0-000 (including)
Web_security_appliance Cisco 8.8.0-085 (including) 8.8.0-085 (including)
Web_security_appliance Cisco 9.0.0-193 (including) 9.0.0-193 (including)
Web_security_appliance Cisco 9.0_base (including) 9.0_base (including)
Web_security_appliance Cisco 9.1.0-000 (including) 9.1.0-000 (including)
Web_security_appliance Cisco 9.1.0-070 (including) 9.1.0-070 (including)
Web_security_appliance Cisco 9.1_base (including) 9.1_base (including)
Web_security_appliance Cisco 9.5.0-235 (including) 9.5.0-235 (including)
Web_security_appliance Cisco 9.5.0-284 (including) 9.5.0-284 (including)
Web_security_appliance Cisco 9.5.0-444 (including) 9.5.0-444 (including)
Web_security_appliance Cisco 9.5_base (including) 9.5_base (including)

References