Denial-of-Service Vulnerability in Cisco WAAS Appliances
CVE-2017-12256

6.5MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
5 October 2017

Summary

A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances enables a remote attacker to trigger a denial-of-service (DoS) condition. The issue arises from specific inefficiencies in file handling within the system. By directing client systems to a corrupted file that cannot be correctly decompressed, an attacker could exploit this vulnerability, leading to device crashes or hangs. This condition may necessitate manual intervention to restore normal operations. For further details, see Cisco's security advisory.

Affected Version(s)

Cisco Wide Area Application Services Cisco Wide Area Application Services

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.