Memory Exhaustion in Cisco Web Security Appliances Due to Improper Management
CVE-2018-0410
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 August 2018
What is CVE-2018-0410?
A vulnerability exists in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances, allowing unauthenticated remote attackers to exploit memory resource management flaws. By leveraging the ability to establish numerous TCP connections to the affected device's data interface using either IPv4 or IPv6, an attacker could lead the system to exhaust its memory. This exploitation results in a denial of service, potentially halting new connection processing and requiring manual intervention for system recovery.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AsyncOS Software for Cisco Web Security Appliances = unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved