CVE-2016-1381
published 2016-05-25CVE-2016-1381: Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.39%
69.3th percentile
Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance_cached_range_request | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
ghsa·2024-10-02
CVE-2024-47805 [MEDIUM] CWE-200 Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type (e.g., Certificate credentials, or Secret file credentials from Plain Credentials Plugin) when accessing item `config.xml` via REST API or CLI.
This allows attackers with Item/Extended Read permission to view encrypted `SecretBytes` values in credentials.
This issue is similar to SECURITY-266 in the 2016-05-11 security advisory, which applied to the `Secret` type used for inline secrets and some credentials types.
Credentials Plugin 1381.v2c3a_12074da_b_ redacts the encrypted values of credentials using the `Sec
GHSA
GHSA-c4wh-vx9c-g273: Memory leak in Cisco AsyncOS 8
ghsa_unreviewed·2022-05-17
CVE-2016-1381 [HIGH] GHSA-c4wh-vx9c-g273: Memory leak in Cisco AsyncOS 8
Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.
Cisco
Cisco Web Security Appliance Cached Range Request Denial of Service Vulnerability
vendor_cisco·2016-05-18·CVSS 7.8
CVE-2016-1381 [HIGH] Cisco Web Security Appliance Cached Range Request Denial of Service Vulnerability
Cisco Web Security Appliance Cached Range Request Denial of Service Vulnerability
A vulnerability in the cached file-range request functionality of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an appliance due to the appliance running out of system memory.
The vulnerability is due to a failure to free memory when a file range for cached content is requested through the WSA. An attacker could exploit this vulnerability by opening multiple connections that request file ranges through the affected device. A successful exploit could allow the attacker to cause the WSA to stop passing traffic when enough memory is used and not freed.
Cisco has released software updates that address this vu
Cisco
Cisco Web Security Appliance Cached Range Request Denial of Service Vulnerability
vendor_cisco
CVE-2016-1381 Cisco Web Security Appliance Cached Range Request Denial of Service Vulnerability
CVE-2016-1381: Cisco Web Security Appliance Cached Range Request Denial of Service Vulnerability
A vulnerability in the cached file-range request functionality of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an appliance due to the appliance running out of system memory. The vulnerability is due to a failure to free memory when a file range for cached content is requested through the WSA. An attacker could exploit this vulnerability by opening multiple connections that request file ranges through the affected device. A successful exploit could allow the attacker to cause the WSA to stop passing traffic when enough memory is used and not freed. Cisco has released software updates that add
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-05-25
Published