Denial of Service Vulnerability in Cisco WAAS Product
CVE-2016-6437

5.9MEDIUM

Key Information:

Summary

A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) can enable unauthenticated, remote attackers to trigger a denial of service (DoS) condition. This issue arises when excessive disk space is consumed, leading to noticeable performance degradation for users. The problem affects specific software versions, which should be updated to known fixed releases to mitigate the risk.

Affected Version(s)

Cisco Wide Area Application Services (WAAS) before 5.3(5g)1 and 6.x before 6.2(2.32) Cisco Wide Area Application Services (WAAS) before 5.3(5g)1 and 6.x before 6.2(2.32)

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.