Lucene search

K
cveCiscoCVE-2013-5537
HistoryOct 24, 2013 - 10:53 a.m.

CVE-2013-5537

2013-10-2410:53:09
CWE-20
cisco
web.nvd.nist.gov
29
cisco
wsa
esa
sma
web framework
denial of service
dos
tcp connections
cve-2013-5537

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

49.5%

The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does not properly manage the state of HTTP and HTTPS sessions, which allows remote attackers to cause a denial of service (management GUI outage) via multiple TCP connections, aka Bug IDs CSCuj59411, CSCuf89818, and CSCuh05635.

Affected configurations

Nvd
Node
ciscoweb_security_applianceMatch-
Node
ciscocontent_security_management_applianceMatch-
Node
ciscoemail_security_appliance_firmwareMatch-
VendorProductVersionCPE
ciscoweb_security_appliance-cpe:2.3:h:cisco:web_security_appliance:-:*:*:*:*:*:*:*
ciscocontent_security_management_appliance-cpe:2.3:h:cisco:content_security_management_appliance:-:*:*:*:*:*:*:*
ciscoemail_security_appliance_firmware-cpe:2.3:o:cisco:email_security_appliance_firmware:-:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

49.5%

Related for CVE-2013-5537