cisco-sa-20161012-waas

Cisco Wide Area Application Services Central Manager Denial of Service Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performance degradation. The vulnerability is due to a lack of file size limitations for SSL system files stored on the disk. An attacker could exploit this vulnerability by sending a continuous stream of SSL traffic to the targeted device. An exploit could allow the attacker to cause a DoS condition due to the adverse impact on device performance. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.