Cisco Web Security Appliance vulnerabilities
57 known vulnerabilities affecting cisco/web_security_appliance.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH26MEDIUM29
Vulnerabilities
Page 1 of 3
CVE-2023-20032P2CRITICALCVSS 9.8fixed in 12.5.6≥ 14.0.0, < 14.0.4-005+2 more2023-03-01
CVE-2023-20032 [CRITICAL] CWE-120 CVE-2023-20032: On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vu
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code.
This vulnerability is due to a missing buffer size chec
nvd
CVE-2021-1359P2HIGHCVSS 8.8v11.8.0-429v11.8.0-4532021-07-08
CVE-2021-1359 [HIGH] CWE-112 CVE-2021-1359: A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (W
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerabil
nvd
CVE-2019-15956P3HIGHCVSS 8.8v10.5.2-072v11.5.1-fcs-125+1 more2019-11-26
CVE-2019-15956 [HIGH] CWE-284 CVE-2019-15956: A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security App
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web management interface. An attacker could e
nvd
CVE-2018-0410P3HIGHCVSS 8.6v9.1.1-074v9.1.2-010+8 more2018-08-15
CVE-2018-0410 [HIGH] CWE-400 CVE-2018-0410: A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appl
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected software improperly manages memory resources for TCP connect
nvd
CVE-2018-0353P3HIGHCVSS 7.5v10.5.1v10.5.1-296+3 more2018-06-07
CVE-2018-0353 [HIGH] CWE-254 CVE-2018-0353: A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an
A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to circumvent Layer 4 Traffic Monitor (L4TM) functionality and bypass security protections. The vulnerability is due to a change in the underlying operating system software that is responsible for monitoring affected traf
nvd
CVE-2017-6746P3HIGHCVSS 7.2v10.0.0-233v10.0_base+9 more2017-07-25
CVE-2017-6746 [HIGH] CWE-20 CVE-2017-6746: A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an authen
A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid administrator credentials. Affected Products: Cisco AsyncOS Software 10.0 and later for WSA on both virtual and hardware applian
nvd
CVE-2017-6751P3HIGHCVSS 7.5v9.0.0-162v9.0.0-193+4 more2017-07-25
CVE-2017-6751 [HIGH] CWE-20 CVE-2017-6751: A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow
A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface of an affected device to the administrative management interface of an affected device, aka an Access Control Bypass Vulnerability. Affected Products: virtual and hardware
nvd
CVE-2019-1886P3HIGHCVSS 8.6v10.5.2-072v10.5.3-025+1 more2019-07-04
CVE-2019-1886 [HIGH] CWE-20 CVE-2019-1886: A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this vulnerability by installing a malformed ce
nvd
CVE-2017-6750P3HIGHCVSS 7.5v10.0.0-232v10.0.0-233+8 more2017-07-25
CVE-2017-6750 [HIGH] CWE-1188 CVE-2017-6750: A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated
A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI, aka a Static Credentials Vulnerability. Affected Products: virtual and hardware version
nvd
CVE-2016-6372P3HIGHCVSS 7.5v5.6.0-623v6.0.0-000+39 more2016-10-28
CVE-2016-6372 [HIGH] CWE-20 CVE-2016-6372: A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail
A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of the targeted device. Emails that should
nvd
CVE-2016-9212P3HIGHCVSS 7.5v9.0.1-162v9.1.1-0742016-12-14
CVE-2016-9212 [HIGH] CWE-20 CVE-2016-9212: A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS So
A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to connect to a secure website over Secure Sockets Layer (SSL) or Transport Layer Security (TLS), even if the WSA is configured to block connections to the website. Af
nvd
CVE-2019-1816P3HIGHCVSS 7.8v10.5.2-072v11.0.0-641+2 more2019-05-03
CVE-2019-1816 [HIGH] CWE-20 CVE-2019-1816: A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could al
A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The vulnerability is due to insufficient validation of user-supplied input on the web and command-line interface. An attacker could exploit this vulnerability
nvd
CVE-2016-1296P3HIGHCVSS 7.5v8.5.3-055v9.1.0-000+1 more2016-01-20
CVE-2016-1296 [HIGH] CWE-254 CVE-2016-1296: The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, a
The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.
nvd
CVE-2015-6298P3CRITICALCVSS 9.0v8.5.0-4972015-11-06
CVE-2015-6298 [CRITICAL] CWE-78 CVE-2015-6298: The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6
The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authenticated users to obtain root privileges via crafted certificate-generation arguments, aka Bug ID CSCus83445.
nvd
CVE-2016-6360P3HIGHCVSS 7.5v8.8.0-085v9.0.0-193+8 more2016-10-28
CVE-2016-6360 [HIGH] CWE-20 CVE-2016-6360: A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and W
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA)
nvd
CVE-2019-1817P3HIGHCVSS 7.5v11.5.1-fcs-115v11.5.1-fcs-124+2 more2019-05-03
CVE-2019-1817 [HIGH] CWE-20 CVE-2019-1817: A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appl
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of HTTP and HTTPS requests. An attacker could exploit this vulnerability by sending a
nvd
CVE-2016-1405P3HIGHCVSS 7.5v8.8.0-085v9.1.0-070+1 more2016-06-08
CVE-2016-1405 [HIGH] CWE-119 CVE-2016-1405: libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Emai
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv7
nvd
CVE-2016-6469P3HIGHCVSS 7.5v9.0.1-162v9.1.1-0742016-12-14
CVE-2016-6469 [HIGH] CWE-399 CVE-2016-6469: A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could al
A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) vulnerability due to the proxy process unexpectedly restarting. More Information: CSCvb04312. Known Affected Releases: 9.0.1-162 9.1.1-074. Known Fixed Releases: 10.1.0-129 9.1.2-0
nvd
CVE-2015-6321P3HIGHCVSS 7.8v5.6.0-623v6.0.0-000+8 more2015-11-06
CVE-2015-6321 [HIGH] CWE-399 CVE-2015-6321: Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x be
Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before 8.0.8-113 on Web Security Appliance
nvd
CVE-2016-1382P3HIGHCVSS 7.5v5.6.0-623v6.0.0-000+25 more2016-05-25
CVE-2016-1382 [HIGH] CWE-20 CVE-2016-1382: Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandle
Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allows remote attackers to cause a denial of service (proxy-process reload) via a crafted request, aka Bug ID CSCuu02529.
nvd
1 / 3Next →