Severity
7.5HIGH
EPSS
1.4%
top 19.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28
Latest updateMay 17

Description

A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first f

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDcisco/web_security_appliance10 versions+9
CVEListV5cisco_asyncos_through_wsa10.0.0-000Cisco AsyncOS through WSA10.0.0-000

🔴Vulnerability Details

2
GHSA
GHSA-wj9f-9jrq-c6wp: A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauth2022-05-17
CVEList
CVE-2016-6360: A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauth2016-10-28

📋Vendor Advisories

1
Cisco
Cisco Email and Web Security Appliance JAR Advanced Malware Protection DoS Vulnerability2016-10-26

💬Community

1
Bugzilla
CVE-2015-6360 libsrtp: improper handling of CSRC count and extension header length in RTP header2016-04-04
CVE-2016-6360 (HIGH CVSS 7.5) | A vulnerability in Advanced Malware | cvebase.io