QID 317072
Date Published: 2021-10-07
QID 317072: Cisco Web Security Appliance Proxy Service Denial of Service (DoS) Vulnerability (cisco-sa-wsa-dos-fmHdKswk)
A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA)
could allow an unauthenticated, remote attacker to exhaust
system memory and cause a denial of service (DoS) condition on an affected device.
Affected Products
Cisco AsyncOS for Cisco WSA, both virtual and hardware appliances.
From 12.0 Prior to 12.0.3-005
From 12.5 Prior to 12.5.2-007
From 14.0 Prior to 14.0.1-014
Note:Potential detection as cannot check the workaround.
QID Detection Logic (Authenticated):
The Qid checks for the Vulnerable version of Cisco WSA in the response of "version" command.
A successful exploit could allow the attacker to cause the system to stop processing new connections, which could result in a DoS condition.
Customers are advised to refer to cisco-sa-wsa-dos-fmHdKswk for more information.Workaround:
There is a workaround that addresses this vulnerability. Customers can use the hidden diagnostic > PROXY > KICK command to restart the proxy process and reclaim memory.
- cisco-sa-wsa-dos-fmHdKswk -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-dos-fmHdKswk
CVEs related to QID 317072
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-wsa-dos-fmHdKswk |
|