Memory Exhaustion in Cisco Web Security Appliances Due to Improper Management
CVE-2018-0410
8.6HIGH
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 August 2018
What is CVE-2018-0410?
A vulnerability exists in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances, allowing unauthenticated remote attackers to exploit memory resource management flaws. By leveraging the ability to establish numerous TCP connections to the affected device's data interface using either IPv4 or IPv6, an attacker could lead the system to exhaust its memory. This exploitation results in a denial of service, potentially halting new connection processing and requiring manual intervention for system recovery.
Affected Version(s)
AsyncOS Software for Cisco Web Security Appliances = unspecified