QID 317072

Date Published: 2021-10-07

QID 317072: Cisco Web Security Appliance Proxy Service Denial of Service (DoS) Vulnerability (cisco-sa-wsa-dos-fmHdKswk)

A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA)
could allow an unauthenticated, remote attacker to exhaust
system memory and cause a denial of service (DoS) condition on an affected device.

Affected Products
Cisco AsyncOS for Cisco WSA, both virtual and hardware appliances.
From 12.0 Prior to 12.0.3-005 From 12.5 Prior to 12.5.2-007 From 14.0 Prior to 14.0.1-014 Note:Potential detection as cannot check the workaround.

QID Detection Logic (Authenticated):
The Qid checks for the Vulnerable version of Cisco WSA in the response of "version" command.

A successful exploit could allow the attacker to cause the system to stop processing new connections, which could result in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-wsa-dos-fmHdKswk for more information.Workaround:
    There is a workaround that addresses this vulnerability. Customers can use the hidden diagnostic > PROXY > KICK command to restart the proxy process and reclaim memory.

    CVEs related to QID 317072

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-wsa-dos-fmHdKswk URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-dos-fmHdKswk