Denial of Service Vulnerability in Cisco Wide Area Application Services
CVE-2017-12250

5.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
21 September 2017

Summary

A vulnerability exists in the HTTP web interface of Cisco's Wide Area Application Services, which can be exploited by remote attackers without authentication. By sending a specially crafted HTTP request, an attacker can trigger a restart of an HTTP Application Optimization process. This exploit can lead to a temporary denial of service, as the WAAS may drop traffic while the process is restarting. Effective input validation measures are lacking, making the device susceptible to such attacks.

Affected Version(s)

Cisco Wide Area Application Services Cisco Wide Area Application Services

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.