CVE-2015-6290
published 2015-09-14CVE-2015-6290: Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.41%
69.6th percentile
Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Web Security Appliance Malformed HTTP Response Denial of Service Vulnerability
vendor_cisco·2015-09-09·CVSS 4.3
CVE-2015-6290 [MEDIUM] CWE-119 Cisco Web Security Appliance Malformed HTTP Response Denial of Service Vulnerability
Cisco Web Security Appliance Malformed HTTP Response Denial of Service Vulnerability
A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to memory management failures during processing of TCP connections.
The vulnerability is due to the improper handling of a malformed HTTP server responses. An unauthenticated, remote attacker with a privileged network position could exploit the vulnerability by conducting a man-in-the-middle (MitM) attack and supplying malformed HTTP server responses to the vulnerable device. A successful exploit could allow the attacker to cause the device to improperly close TCP connections and fail to free memory resources, resulting in
GHSA
GHSA-h7qw-5c46-g9j3: Cisco Web Security Appliance (WSA) 8
ghsa_unreviewed·2022-05-17
CVE-2015-6290 [MEDIUM] CWE-119 GHSA-h7qw-5c46-g9j3: Cisco Web Security Appliance (WSA) 8
Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-14
Published