CVE-2015-6321

CWE-3994 documents4 sources
Severity
7.8HIGH
EPSS
0.6%
top 31.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateMay 17

Description

Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before 8.0.8-113 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug IDs CSCus79774, CSCus

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-rmcx-cqh3-x8cj: Cisco AsyncOS before 82022-05-17
CVEList
CVE-2015-6321: Cisco AsyncOS before 82015-11-06

📋Vendor Advisories

1
Cisco
Cisco AsyncOS TCP Flood Denial of Service Vulnerability2015-11-04
CVE-2015-6321 (HIGH CVSS 7.8) | Cisco AsyncOS before 8.5.7-042 | cvebase.io