Cisco AsyncOS Denial of Service Vulnerability (CVE-2016-1382)
Cisco AsyncOS Denial of Service Vulnerability (CVE-2016-1382)
Release date:
Updated on:
Affected Systems:
Cisco AsyncOS <= 8.8
Description:
CVE (CAN) ID: CVE-2016-1382
The Cisco AsyncOS operating system improves the security and performance of Cisco email security devices.
On the WSA device, Cisco AsyncOS <8.5.3-069, 8.6 <= 8.8 handle the HTTP request Memory Allocation Error. Remote attackers can initiate DoS (memory depletion) by constructing requests ).
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160518-wsa3
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20160518-wsa3) and patches for this:
Cisco-sa-20160518-wsa3: Cisco Web Security Appliance HTTP Length Denial of Service Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160518-wsa3
This article permanently updates the link address: