cisco-sa-20160518-wsa1
Cisco Web Security Appliance HTTP POST Denial of Service Vulnerability
High · Updated · Cisco
1 product with CSAF evidence
A vulnerability that occurs when parsing an HTTP POST request with Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) vulnerability due to the proxy process becoming unresponsive. The vulnerability is due to a lack of proper input validation of the packets that make up the HTTP POST request. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the affected device. An exploit could allow the attacker to cause a DoS condition due to the proxy process becoming unresponsive and the WSA reloading. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
| Product | CVE |
|---|---|
| Cisco Web Security Appliance (WSA) | CVE-2016-1380 |