CVE-2016-1383Missing Release of Memory after Effective Lifetime in Cisco WEB Security Appliance

CWE-3994 documents4 sources
Severity
7.5HIGHNVD
EPSS
1.1%
top 21.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 25
Latest updateMay 17

Description

Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDcisco/web_security_appliance27 versions+26

🔴Vulnerability Details

2
GHSA
GHSA-xqf6-m6vx-v7jx: Memory leak in Cisco AsyncOS through 82022-05-17
CVEList
CVE-2016-1383: Memory leak in Cisco AsyncOS through 82016-05-25

📋Vendor Advisories

1
Cisco
Cisco Web Security Appliance Connection Denial of Service Vulnerability2016-05-18
CVE-2016-1383 — Cisco vulnerability | cvebase