7.8
CVSSv2

CVE-2015-6293

Published: 06/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco AsyncOS 8.x prior to 8.0.8-113, 8.1.x and 8.5.x prior to 8.5.3-051, 8.6.x and 8.7.x prior to 8.7.0-171-LD, and 8.8.x prior to 8.8.0-085 on Web Security Appliance (WSA) devices allows remote malicious users to cause a denial of service (memory consumption) via multiple file-range requests, aka Bug ID CSCur39155.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco web security appliance 8.0.6

cisco web security appliance 8.5.0.000

cisco web security appliance 8.0.0-000

cisco web security appliance 8.0.8-mr-113

cisco web security appliance 8.0.7-142

cisco web security appliance 8.0.5

cisco web security appliance 8.5.2-024

cisco web security appliance 8.5.0-497

cisco web security appliance 8.0.6-078

Vendor Advisories

A vulnerability in the file-range request functionality of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an appliance because the appliance runs out of system memory The vulnerability is due to a failure to free memory when a file range is reque ...