Denial of Service Vulnerability in Cisco Wide Area Application Services
CVE-2017-12250
5.3MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 21 September 2017
Summary
A vulnerability exists in the HTTP web interface of Cisco's Wide Area Application Services, which can be exploited by remote attackers without authentication. By sending a specially crafted HTTP request, an attacker can trigger a restart of an HTTP Application Optimization process. This exploit can lead to a temporary denial of service, as the WAAS may drop traffic while the process is restarting. Effective input validation measures are lacking, making the device susceptible to such attacks.
Affected Version(s)
Cisco Wide Area Application Services Cisco Wide Area Application Services
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved