4.3
CVSSv2

CVE-2016-6416

Published: 05/10/2016 Updated: 30/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 up to and including 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 up to and including 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote malicious users to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz86065.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco content security management appliance 9.1.0-033

cisco email security appliance 9.9_base

cisco web security appliance 9.5.0-235

cisco web security appliance 9.5.0-284

cisco email security appliance 9.6.0-051

cisco email security appliance 9.7.1-066

cisco content security management appliance 9.1.0-031

cisco email security appliance 9.9.6-026

cisco content security management appliance 9.1.0-103

cisco content security management appliance 9.6.0

cisco web security appliance 9.5_base

cisco content security management appliance 9.1.0-004

cisco content security management appliance 9.1.0

cisco web security appliance 9.5.0-444

cisco web security appliance 9.1.0-000

cisco web security appliance 9.1.0-070

cisco web security appliance 9.0.0-162

cisco content security management appliance 9.5.0

cisco email security appliance 9.6.0-000

cisco web security appliance 9.1_base

cisco email security appliance 9.6.0-042

Vendor Advisories

A vulnerability in the local File Transfer Protocol (FTP) service on the Cisco AsyncOS for Email Security Appliance (ESA), Web Security Appliance (WSA), and Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition The vulnerability is due to lack of throttling of FTP ...