CVE-2016-6360
published 2016-10-28CVE-2016-6360: A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.16%
80.2th percentile
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | email_and_web_security_appliance_jar_advanced_malware_protection_dos | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Email and Web Security Appliance JAR Advanced Malware Protection DoS Vulnerability
vendor_cisco·2016-10-26·CVSS 5.0
CVE-2016-6360 [MEDIUM] CWE-119 Cisco Email and Web Security Appliance JAR Advanced Malware Protection DoS Vulnerability
Cisco Email and Web Security Appliance JAR Advanced Malware Protection DoS Vulnerability
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting.
The vulnerability is due to improper validation of a Java Archive (JAR) file that is scanned when AMP is configured. An attacker could exploit this vulnerability by crafting a JAR file and attaching this JAR file to an email that is then sent through the ESA, or allowing the JAR file to be download from the web through the WSA. An exploit could allow the attacker to cause the Cisco ESA and WSA AMP process to unexpectedly restar
Cisco
Cisco Email and Web Security Appliance JAR Advanced Malware Protection DoS Vulnerability
vendor_cisco
CVE-2016-6360 Cisco Email and Web Security Appliance JAR Advanced Malware Protection DoS Vulnerability
CVE-2016-6360: Cisco Email and Web Security Appliance JAR Advanced Malware Protection DoS Vulnerability
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. The vulnerability is due to improper validation of a Java Archive (JAR) file that is scanned when AMP is configured. An attacker could exploit this vulnerability by crafting a JAR file and attaching this JAR file to an email that is then sent through the ESA, or allowing the JAR file to be download from the web through the WSA. An exploit could allow the attacker to cause the Cisco ESA and WSA AMP process to unexpe
GHSA
GHSA-wj9f-9jrq-c6wp: A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauth
ghsa_unreviewed·2022-05-17
CVE-2016-6360 [HIGH] CWE-20 GHSA-wj9f-9jrq-c6wp: A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauth
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/93910http://www.securitytracker.com/id/1037120http://www.securitytracker.com/id/1037121https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-esawsa3http://www.securityfocus.com/bid/93910http://www.securitytracker.com/id/1037120http://www.securitytracker.com/id/1037121https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-esawsa3
2016-10-28
Published