CVE-2015-6287
published 2015-09-14CVE-2015-6287: Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service outage) via a flood of TCP traffic…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.04%
78.9th percentile
Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service outage) via a flood of TCP traffic that leads to DNS resolution delays, aka Bug IDs CSCur32005 and CSCur07907.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r224-hwf4-6cww: Cisco Web Security Appliance (WSA) 8
ghsa_unreviewed·2022-05-17
CVE-2015-6287 [MEDIUM] GHSA-r224-hwf4-6cww: Cisco Web Security Appliance (WSA) 8
Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service outage) via a flood of TCP traffic that leads to DNS resolution delays, aka Bug IDs CSCur32005 and CSCur07907.
Cisco
Cisco Web Security Appliance DNS Resolution Vulnerability
vendor_cisco·2015-09-09·CVSS 5.0
CVE-2015-6287 [MEDIUM] CWE-399 Cisco Web Security Appliance DNS Resolution Vulnerability
Cisco Web Security Appliance DNS Resolution Vulnerability
A vulnerability in the DNS resolution function of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to DNS name resolution failing through the device.
The vulnerability is due to the handling of DNS requests awaiting a DNS response when new, incoming DNS requests are received. An attacker could exploit this vulnerability by sending TCP proxy traffic to the WSA at a high rate. An exploit could allow the attacker to cause a partial DoS condition because DNS name resolution fails, which results in the client receiving a HTTP 503 ''Service Unavailable'' error.
Cisco has confirmed the vulnerability and released software updates.
To exploit
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-14
Published