5
CVSSv2

CVE-2019-1817

Published: 03/05/2019 Updated: 24/03/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote malicious user to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of HTTP and HTTPS requests. An attacker could exploit this vulnerability by sending a malformed HTTP or HTTPS request to an affected device. An exploit could allow the malicious user to cause a restart of the web proxy process, resulting in a temporary DoS condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco web security appliance 11.5.1-fcs-115

cisco web security appliance 11.5.1-fcs-124

cisco web security appliance 11.5.1-fcs-125

cisco web security appliance 11.7.0-fcs-334

Vendor Advisories

A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device The vulnerability is due to improper validation of HTTP and HTTPS requests An attacker could exploit this vulnerability by send ...