QID 317079

Date Published: 2021-11-16

QID 317079: Cisco Web Security Appliance Proxy Service Denial of Service (DoS) Vulnerability (cisco-sa-wsa-dos-fmHdKswk)

A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA)
could allow an unauthenticated, remote attacker to exhaust
system memory and cause a denial of service (DoS) condition on an affected device.

Affected Products
Cisco AsyncOS for Cisco WSA, both virtual and hardware appliances.
Vulnerable releases:
From 12.0 Prior to 12.0.3-005
From 12.5 Prior to 12.5.2-011
From 14.0 Prior to 14.0.1-053

QID Detection Logic (Authenticated):
The Qid checks for the Vulnerable version of Cisco WSA in the response of "version" command.

A successful exploit could allow the attacker to cause the system to stop processing new connections, which could result in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-wsa-dos-fmHdKswk for more information.

    CVEs related to QID 317079

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-wsa-dos-fmHdKswk URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-dos-fmHdKswk