CVE-2016-6437
published 2016-10-27CVE-2016-6437: A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a…
PriorityP428medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.73%
74.9th percentile
A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performance degradation. More Information: CSCva03095. Known Affected Releases: 5.3(5), 6.1(1), 6.2(1). Known Fixed Releases: 5.3(5g)1, 6.2(2.32).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services_central_manager | — | — |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2020-6437
vendor_chrome·2020-04-07·CVSS 4.3
CVE-2020-6437 [LOW] Stable Channel Update for Desktop: CVE-2020-6437
Stable Channel Update for Desktop
CVE-2020-6437: Inappropriate implementation in WebView. Reported by Jann Horn on 2016-08-19
[$500][ 714617 ] Low CVE-2020-6438: Insufficient policy enforcement in extensions
Reported by Ng Yik Phang on 2017-04-24
Severity: low
Cisco
Cisco Wide Area Application Services Central Manager Denial of Service Vulnerability
vendor_cisco·2016-10-12·CVSS 4.3
CVE-2016-6437 [MEDIUM] CWE-399 Cisco Wide Area Application Services Central Manager Denial of Service Vulnerability
Cisco Wide Area Application Services Central Manager Denial of Service Vulnerability
A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performance degradation.
The vulnerability is due to a lack of file size limitations for SSL system files stored on the disk. An attacker could exploit this vulnerability by sending a continuous stream of SSL traffic to the targeted device. An exploit could allow the attacker to cause a DoS condition due to the adverse impact on device performance.
Cisco has released software updates that address this vulnerability. There are workarounds that address this
Cisco
Cisco Wide Area Application Services Central Manager Denial of Service Vulnerability
vendor_cisco
CVE-2016-6437 Cisco Wide Area Application Services Central Manager Denial of Service Vulnerability
CVE-2016-6437: Cisco Wide Area Application Services Central Manager Denial of Service Vulnerability
A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performance degradation. The vulnerability is due to a lack of file size limitations for SSL system files stored on the disk. An attacker could exploit this vulnerability by sending a continuous stream of SSL traffic to the targeted device. An exploit could allow the attacker to cause a DoS condition due to the adverse impact on device performance. Cisco has released software updates that address this vulnerability. There are
CWE: CWE-399, CWE-
GHSA
GHSA-mpwr-fprg-72gv: A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to
ghsa_unreviewed·2022-05-17
CVE-2016-6437 [HIGH] GHSA-mpwr-fprg-72gv: A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to
A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performance degradation. More Information: CSCva03095. Known Affected Releases: 5.3(5), 6.1(1), 6.2(1). Known Fixed Releases: 5.3(5g)1, 6.2(2.32).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93524http://www.securitytracker.com/id/1037002https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-waashttp://www.securityfocus.com/bid/93524http://www.securitytracker.com/id/1037002https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-waas
2016-10-27
Published