QID 316996
Date Published: 2021-07-12
QID 316996: Cisco Web Security Appliance Vulnerability in Open Secure Sockets Layer (OpenSSL) Affecting Cisco Products (cisco-sa-openssl-2021-GHY28dJd)
Cisco Web Security Appliance is impacted by CVE-2021-3449, OpenSSL NULL Pointer Dereference Denial of Service Vulnerability
that could allow an attacker to cause a denial of service (DoS) condition on a targeted system.
Affected Products
Cisco Web Security Appliance following releases:
Prior to 12.0.3-005
From 12.5 Prior to 12.5.2-007
From 14.0 Prior to 14.0.1-040
QID Detection Logic (Authenticated):
The Qid checks for the Vulnerable version of Cisco WSA in the response of "version" command.
Successful exploitation could allow a remote unauthenticated attacker to crash a TLS server resulting in a Denial of Service (DoS) condition.
Solution
Customers are advised to refer to cisco-sa-openssl-2021-GHY28dJd for more information.
Vendor References
- cisco-sa-openssl-2021-GHY28dJd -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
CVEs related to QID 316996
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-openssl-2021-GHY28dJd |
|