5
CVSSv2

CVE-2015-6386

Published: 01/12/2015 Updated: 14/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote malicious users to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer, aka Bug ID CSCut94150.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco web security appliance 8.0.7-142

cisco web security appliance 8.5.1-021

Vendor Advisories

A vulnerability in the native passthrough FTP functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to high CPU utilization The vulnerability occurs when the FTP client terminates the FTP control connection when the data transfer is complete ...