CVE-2016-9212
published 2016-12-14CVE-2016-9212: A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.79%
84.8th percentile
A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to connect to a secure website over Secure Sockets Layer (SSL) or Transport Layer Security (TLS), even if the WSA is configured to block connections to the website. Affected Products: This vulnerability affects Cisco Web Security Appliances if the HTTPS decryption options are enabled and configured for the device to block connections to certain websites. More Information: CSCvb49012. Known Affected Releases: 9.0.1-162 9.1.1-074.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance_drop_decrypt_policy | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Web Security Appliance Drop Decrypt Policy Bypass Vulnerability
vendor_cisco·2016-12-07·CVSS 4.3
CVE-2016-9212 [MEDIUM] CWE-20 Cisco Web Security Appliance Drop Decrypt Policy Bypass Vulnerability
Cisco Web Security Appliance Drop Decrypt Policy Bypass Vulnerability
A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to connect to a secure website over Secure Sockets Layer (SSL) or Transport Layer Security (TLS), even if the WSA is configured to block connections to the website.
The vulnerability is due to incomplete input validation of HTTP headers. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to connect to a website that should be blocked.
There are no workarounds that address this vulnerability.
This advisory is available at the follow
Cisco
Cisco Web Security Appliance Drop Decrypt Policy Bypass Vulnerability
vendor_cisco
CVE-2016-9212 Cisco Web Security Appliance Drop Decrypt Policy Bypass Vulnerability
CVE-2016-9212: Cisco Web Security Appliance Drop Decrypt Policy Bypass Vulnerability
A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to connect to a secure website over Secure Sockets Layer (SSL) or Transport Layer Security (TLS), even if the WSA is configured to block connections to the website. The vulnerability is due to incomplete input validation of HTTP headers. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to connect to a website that should be blocked. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCvb49012, CSCvg22495
GHSA
GHSA-334p-wmh8-9fqw: A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could all
ghsa_unreviewed·2022-05-17
CVE-2016-9212 [HIGH] CWE-20 GHSA-334p-wmh8-9fqw: A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could all
A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to connect to a secure website over Secure Sockets Layer (SSL) or Transport Layer Security (TLS), even if the WSA is configured to block connections to the website. Affected Products: This vulnerability affects Cisco Web Security Appliances if the HTTPS decryption options are enabled and configured for the device to block connections to certain websites. More Information: CSCvb49012. Known Affected Releases: 9.0.1-162 9.1.1-074.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/94774http://www.securitytracker.com/id/1037410https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-wsa1http://www.securityfocus.com/bid/94774http://www.securitytracker.com/id/1037410https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-wsa1
2016-12-14
Published