CVE-2016-6416
published 2016-10-05CVE-2016-6416: The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
2.02%
78.9th percentile
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz86065.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos_file_transfer_protocol | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco AsyncOS File Transfer Protocol Denial of Service Vulnerability
vendor_cisco·2016-09-28·CVSS 4.3
CVE-2016-6416 [MEDIUM] CWE-119 Cisco AsyncOS File Transfer Protocol Denial of Service Vulnerability
Cisco AsyncOS File Transfer Protocol Denial of Service Vulnerability
A vulnerability in the local File Transfer Protocol (FTP) service on the Cisco AsyncOS for Email Security Appliance (ESA), Web Security Appliance (WSA), and Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to lack of throttling of FTP connections. An attacker could exploit this vulnerability by sending a flood of FTP traffic to the local FTP service on the targeted device. An exploit could allow the attacker to cause a DoS condition.
CONDITION(s):
The local FTP service is enabled. This is not the default configuration.
To check if local FTP service is enabled, the administrator can use either the GUI or c
Cisco
Cisco AsyncOS File Transfer Protocol Denial of Service Vulnerability
vendor_cisco
CVE-2016-6416 Cisco AsyncOS File Transfer Protocol Denial of Service Vulnerability
CVE-2016-6416: Cisco AsyncOS File Transfer Protocol Denial of Service Vulnerability
A vulnerability in the local File Transfer Protocol (FTP) service on the Cisco AsyncOS for Email Security Appliance (ESA), Web Security Appliance (WSA), and Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to lack of throttling of FTP connections. An attacker could exploit this vulnerability by sending a flood of FTP traffic to the local FTP service on the targeted device. An exploit could allow the attacker to cause a DoS condition. CONDITION(s): The local FTP service is enabled. This is not the default configuration. To check if local FTP service is enabled, the administrator can use either th
GHSA
GHSA-7cpm-6ch9-5qff: The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9
ghsa_unreviewed·2022-05-17
CVE-2016-6416 [MEDIUM] CWE-119 GHSA-7cpm-6ch9-5qff: The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz86065.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-aoshttp://www.securityfocus.com/bid/93198http://www.securitytracker.com/id/1036915http://www.securitytracker.com/id/1036916http://www.securitytracker.com/id/1036917http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-aoshttp://www.securityfocus.com/bid/93198http://www.securitytracker.com/id/1036915http://www.securitytracker.com/id/1036916http://www.securitytracker.com/id/1036917
2016-10-05
Published