Cisco AsyncOS Memory leakage Denial of Service Vulnerability (CVE-2016-1383)
Cisco AsyncOS Memory leakage Denial of Service Vulnerability (CVE-2016-1383)
Release date:
Updated on:
Affected Systems:
Cisco AsyncOS <= 8.8
Description:
CVE (CAN) ID: CVE-2016-1383
The Cisco AsyncOS operating system improves the security and performance of Cisco email security devices.
On the WSA device, Cisco AsyncOS <= 8.8 has memory leakage. Remote attackers use HTTP status code to cause DoS (memory depletion ).
<* Source: Cisco
Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160518-wsa4
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20160518-wsa4) and patches for this:
Cisco-sa-20160518-wsa4: Cisco Web Security Appliance Connection Denial of Service Vulnerability
Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160518-wsa4
This article permanently updates the link address: