cbcvebase.

Cisco Web Security Appliance vulnerabilities

57 known vulnerabilities affecting cisco/web_security_appliance.

Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH26MEDIUM29

Vulnerabilities

Page 2 of 3
CVE-2015-6293P3HIGHCVSS 7.8v8.0.0-000v8.0.5+7 more2015-11-06
CVE-2015-6293 [HIGH] CWE-399 CVE-2015-6293: Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-1 Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple file-range requests, aka Bug ID CSCur39155.
nvd
CVE-2016-6407P3HIGHCVSS 7.5v5.6.0-623v6.0.0-000+39 more2016-09-17
CVE-2016-6407 [HIGH] CWE-399 CVE-2016-6407: Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to c Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219.
nvd
CVE-2015-6292P3HIGHCVSS 7.8v8.0.0-000v8.0.5+4 more2015-11-06
CVE-2015-6292 [HIGH] CWE-399 CVE-2015-6292: The proxy-cache implementation in Cisco AsyncOS 8.0.x before 8.0.7-151, 8.1.x and 8.5.x before 8.5.2 The proxy-cache implementation in Cisco AsyncOS 8.0.x before 8.0.7-151, 8.1.x and 8.5.x before 8.5.2-004, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple proxy connections, aka Bug ID CSCus10922.
nvd
CVE-2016-1380P3HIGHCVSS 7.5v8.0.0-000v8.0.5+12 more2016-05-25
CVE-2016-1380 [HIGH] CWE-20 CVE-2016-1380: Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers t Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171.
nvd
CVE-2016-1381P3HIGHCVSS 7.5v8.5.0-497v8.5.0.000+8 more2016-05-25
CVE-2016-1381 [HIGH] CWE-399 CVE-2016-1381: Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) device Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.
nvd
CVE-2015-0692P3HIGHCVSS 7.2v8.5_base2015-04-11
CVE-2015-0692 [HIGH] CWE-264 CVE-2015-0692: Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via crafted serialized objects, aka Bug ID CSCut39230.
nvd
CVE-2019-1884P3MEDIUMCVSS 6.5v10.1.4-017v10.5.2-072+2 more2019-07-04
CVE-2019-1884 [MEDIUM] CWE-20 CVE-2019-1884: A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appl A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in HTTP/HTTPS requests sent through an a
nvd
CVE-2016-1383P4HIGHCVSS 7.5v5.6.0-623v6.0.0-000+25 more2016-05-25
CVE-2016-1383 [HIGH] CWE-399 CVE-2016-1383: Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attac Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.
nvd
CVE-2015-0693P4HIGHCVSS 7.2v8.5_base2015-04-15
CVE-2015-0693 [HIGH] CWE-20 CVE-2015-0693: Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via a crafted pickle file, aka Bug ID CSCut39259.
nvd
CVE-2017-3827P4MEDIUMCVSS 5.8v10.0.0-082v10.0.0-124+3 more2017-02-22
CVE-2017-3827 [MEDIUM] CWE-20 CVE-2017-3827: A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Softwar A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first f
nvd
CVE-2019-1672P4MEDIUMCVSS 5.8v10.1.0-204v10.5.2-072+1 more2019-02-08
CVE-2019-1672 [MEDIUM] CWE-400 CVE-2019-1672: A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appl A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of SSL-encrypted traffic when Decrypt for
nvd
CVE-2017-3870P4MEDIUMCVSS 5.8v8.5.3-069v9.1.1-074+1 more2017-03-17
CVE-2017-3870 [MEDIUM] CWE-119 CVE-2017-3870: A vulnerability in the URL filtering feature of Cisco AsyncOS Software for Cisco Web Security Applia A vulnerability in the URL filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured URL filter rule. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA
nvd
CVE-2016-1411P4MEDIUMCVSS 5.9v7.7.0-608v7.7.5-835+1 more2016-12-14
CVE-2016-1411 [MEDIUM] CWE-310 CVE-2016-1411: A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appli A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote attacker to impersonate the update server. More Information: CSCul88715, CSCul94617, CSCul94627. Known Affected
nvd
CVE-2021-1129P4MEDIUMCVSS 5.3v11.8.02021-01-20
CVE-2021-1129 [MEDIUM] CWE-201 CVE-2021-1129: A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Sec A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain configuration information from an affected
nvd
CVE-2022-20784P4MEDIUMCVSS 5.3≥ 11.7.0, < 14.0.22022-04-06
CVE-2022-20784 [MEDIUM] CWE-20 CVE-2022-20784: A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies and access blocked content on an affected device. This vulnerability is due to incorrect handling of certain character combinations i
nvd
CVE-2017-6748P4MEDIUMCVSS 6.7v10.0.0-232v10.0.0-233+8 more2017-07-25
CVE-2017-6748 [MEDIUM] CWE-74 CVE-2017-6748: A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authentic A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level or administrator-level credentials. Affected Products: virtual and hardware versions of Cisco Web Security Applianc
nvd
CVE-2018-0428P4MEDIUMCVSS 6.7v11.0.0-fcs-250v11.5.0-fcs-000+2 more2018-08-15
CVE-2018-0428 [MEDIUM] CWE-284 CVE-2018-0428: A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allo A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The vulnerability is due to improper implementation of access controls. An attacker could exploit this vulnerability b
nvd
CVE-2018-0406P4MEDIUMCVSS 6.1v10.1.2-003v10.5.1-269+1 more2018-08-01
CVE-2018-0406 [MEDIUM] CWE-79 CVE-2018-0406: A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could al A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected or Document Object Model based (DOM-based) cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficie
nvd
CVE-2018-0366P4MEDIUMCVSS 6.1v10.1.2-003v10.5.1-2762018-07-16
CVE-2018-0366 [MEDIUM] CWE-79 CVE-2018-0366: A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could al A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the
nvd
CVE-2016-6416P4MEDIUMCVSS 5.9v9.0.0-162v9.1.0-000+6 more2016-10-05
CVE-2016-6416 [MEDIUM] CWE-119 CVE-2016-6416: The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-0 The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz8
nvd
Cisco Web Security Appliance vulnerabilities | cvebase