QID 317402

Date Published: 2023-12-19

QID 317402: Cisco Secure Web Appliance HTTP/2 Rapid Reset Attack Vulnerability (CSCwh88595)

HTTP/2 protocol has weakness which enables attacker to perform distributed denial of service (DDoS) attack technique against Cisco Secure Web Appliance

Affected Products
Cisco Secure Web Appliance:
Version: 15.1.0-287
Version: 15.0.0-364
Version: 14.5.0-321
Version: 14.0.0-335

The QID checks for the Vulnerable version of Cisco Secure Web appliance formerly WSA in the response of "version" command.

Successful exploit could allow attacker to perform DDOS attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CSCwh88595 for more information.

    CVEs related to QID 317402

    Software Advisories
    Advisory ID Software Component Link
    CSCwh88595 URL Logo bst.cloudapps.cisco.com/bugsearch/bug/CSCwh88595