QID 317318
Date Published: 2023-08-09
QID 317318: Cisco Secure Web Appliance Buffer Overflow Vulnerability (CSCwd74132)
This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write. An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device.
Affected Products
Cisco Secure Web Appliance Version 14.5.0-537
The Qid checks for the Vulnerable version of Cisco WSA in the response of "version" command.
A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process, or else crash the process, resulting in a denial of service (DoS) condition.
Solution
Customers are advised to refer to CSCwd74132 for more information.
Vendor References
- CSCwd74132 -
bst.cisco.com/bugsearch/bug/CSCwd74132
CVEs related to QID 317318
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CSCwd74132 |
|