Vulnslist

find the latest Cisco vulnerabilities

Cisco AsyncOS File Transfer Protocol Denial of Service Vulnerability

cisco-sa-20160928-aos · Medium · Published · Updated

A vulnerability in the local File Transfer Protocol (FTP) service on the Cisco AsyncOS for Email Security Appliance (ESA), Web Security Appliance (WSA), and Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to lack of throttling of FTP connections. An attacker could exploit this vulnerability by sending a flood of FTP traffic to the local FTP service on the targeted device. An exploit could allow the attacker to cause a DoS condition. CONDITION(s): The local FTP service is enabled. This is not the default configuration. To check if local FTP service is enabled, the administrator can use either the GUI or command-line interface (CLI). 1. On the GUI, navigate to Network -> IP Interfaces, click the name of the interface, and in the Services section, check if the FTP service is enabled. 2. For the CLI, the parameter “Do you want to enable FTP on this interface?” would be set to Yes. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-aos

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2016-6416
Cisco Bug IDsCSCuz82907, CSCuz84330, CSCuz86065
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P/E:F/RL:U/RC:C
Product Names From Source
Cisco Web Security Appliance (WSA), Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), Cisco Secure Email, Cisco Secure Email and Web Manager, Cisco Secure Web Appliance

Related Products

Product CVE Evidence
Cisco Web Security Appliance (WSA) CVE-2016-6416 Cisco OpenVuln
Cisco Secure Web Appliance CVE-2016-6416 Cisco OpenVuln
Cisco Secure Email and Web Manager CVE-2016-6416 Cisco OpenVuln
Cisco Secure Email CVE-2016-6416 Cisco OpenVuln
Cisco Email Security Appliance (ESA) CVE-2016-6416 Cisco OpenVuln
Cisco Content Security Management Appliance (SMA) CVE-2016-6416 Cisco OpenVuln