Cisco Web Security Appliance vulnerabilities
57 known vulnerabilities affecting cisco/web_security_appliance.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH26MEDIUM29
Vulnerabilities
Page 3 of 3
CVE-2016-1381HIGHCVSS 7.5v8.5.0-497v8.5.0.000+8 more2016-05-25
CVE-2016-1381 [HIGH] CWE-399 CVE-2016-1381: Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) device
Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.
nvd
CVE-2016-1380HIGHCVSS 7.5v8.0.0-000v8.0.5+12 more2016-05-25
CVE-2016-1380 [HIGH] CWE-20 CVE-2016-1380: Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers t
Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171.
nvd
CVE-2016-1383HIGHCVSS 7.5v5.6.0-623v6.0.0-000+25 more2016-05-25
CVE-2016-1383 [HIGH] CWE-399 CVE-2016-1383: Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attac
Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.
nvd
CVE-2016-1288MEDIUMCVSS 5.3v9.0.0-193v8.5.0-4972016-03-03
CVE-2016-1288 [MEDIUM] CWE-20 CVE-2016-1288: The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security A
The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.
nvd
CVE-2016-1296HIGHCVSS 7.5v8.5.3-055v9.1.0-000+1 more2016-01-20
CVE-2016-1296 [HIGH] CWE-254 CVE-2016-1296: The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, a
The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.
nvd
CVE-2015-6386MEDIUMCVSS 5.0v8.0.7-142v8.5.1-0212015-12-01
CVE-2015-6386 [MEDIUM] CWE-399 CVE-2015-6386: The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 an
The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer, aka Bug ID CSCut94150.
nvd
CVE-2015-6298CRITICALCVSS 9.0v8.5.0-4972015-11-06
CVE-2015-6298 [CRITICAL] CWE-78 CVE-2015-6298: The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6
The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authenticated users to obtain root privileges via crafted certificate-generation arguments, aka Bug ID CSCus83445.
nvd
CVE-2015-6293HIGHCVSS 7.8v8.0.0-000v8.0.5+7 more2015-11-06
CVE-2015-6293 [HIGH] CWE-399 CVE-2015-6293: Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-1
Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple file-range requests, aka Bug ID CSCur39155.
nvd
CVE-2015-6292HIGHCVSS 7.8v8.0.0-000v8.0.5+4 more2015-11-06
CVE-2015-6292 [HIGH] CWE-399 CVE-2015-6292: The proxy-cache implementation in Cisco AsyncOS 8.0.x before 8.0.7-151, 8.1.x and 8.5.x before 8.5.2
The proxy-cache implementation in Cisco AsyncOS 8.0.x before 8.0.7-151, 8.1.x and 8.5.x before 8.5.2-004, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple proxy connections, aka Bug ID CSCus10922.
nvd
CVE-2015-6321HIGHCVSS 7.8v5.6.0-623v6.0.0-000+8 more2015-11-06
CVE-2015-6321 [HIGH] CWE-399 CVE-2015-6321: Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x be
Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before 8.0.8-113 on Web Security Appliance
nvd
CVE-2015-4288MEDIUMCVSS 4.3v8.5.0-0002015-07-29
CVE-2015-4288 [MEDIUM] CWE-310 CVE-2015-4288: The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Applianc
The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka B
nvd
CVE-2015-0732MEDIUMCVSS 4.3v9.0.0-1932015-07-29
CVE-2015-0732 [MEDIUM] CWE-79 CVE-2015-0732: Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0-
Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0-193; Email Security Appliance (ESA) 8.5.6-113, 9.1.0-032, 9.1.1-000, and 9.6.0-000; and Content Security Management Appliance (SMA) 9.1.0-033 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuu37
nvd
CVE-2015-4198MEDIUMCVSS 4.3v8.5.0-4972015-06-20
CVE-2015-4198 [MEDIUM] CWE-79 CVE-2015-4198: Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA)
Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header, aka Bug ID CSCuu24409.
nvd
CVE-2015-0738MEDIUMCVSS 4.3v8.5.0-4972015-05-17
CVE-2015-0738 [MEDIUM] CWE-79 CVE-2015-0738: Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appli
Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.
nvd
CVE-2015-0693HIGHCVSS 7.2v8.5_base2015-04-15
CVE-2015-0693 [HIGH] CWE-20 CVE-2015-0693: Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use
Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via a crafted pickle file, aka Bug ID CSCut39259.
nvd
CVE-2015-0698MEDIUMCVSS 4.3≤ 8.5.0-4972015-04-15
CVE-2015-0698 [MEDIUM] CWE-79 CVE-2015-0698: Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cis
Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.
nvd
CVE-2015-0692HIGHCVSS 7.2v8.5_base2015-04-11
CVE-2015-0692 [HIGH] CWE-264 CVE-2015-0692: Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use
Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via crafted serialized objects, aka Bug ID CSCut39230.
nvd
← Previous3 / 3