Denial of Service Vulnerability in Cisco WAAS Product
CVE-2016-6437
5.9MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 27 October 2016
Summary
A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) can enable unauthenticated, remote attackers to trigger a denial of service (DoS) condition. This issue arises when excessive disk space is consumed, leading to noticeable performance degradation for users. The problem affects specific software versions, which should be updated to known fixed releases to mitigate the risk.
Affected Version(s)
Cisco Wide Area Application Services (WAAS) before 5.3(5g)1 and 6.x before 6.2(2.32) Cisco Wide Area Application Services (WAAS) before 5.3(5g)1 and 6.x before 6.2(2.32)
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved