Lucene search

K
cveCiscoCVE-2015-6290
HistorySep 14, 2015 - 1:59 a.m.

CVE-2015-6290

2015-09-1401:59:07
CWE-119
cisco
web.nvd.nist.gov
32
cisco
wsa
8.0.7
remote
http
denial of service
memory consumption
tcp connections
cve-2015-6290

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.8

Confidence

High

EPSS

0.002

Percentile

64.8%

Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.

Affected configurations

Nvd
Node
ciscoweb_security_virtual_applianceMatch8.0.5
OR
ciscoweb_security_virtual_applianceMatch8.0.6
OR
ciscoweb_security_virtual_applianceMatch8.0.7
OR
ciscoweb_security_virtual_applianceMatch8.0_base
VendorProductVersionCPE
ciscoweb_security_virtual_appliance8.0.5cpe:2.3:a:cisco:web_security_virtual_appliance:8.0.5:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance8.0.6cpe:2.3:a:cisco:web_security_virtual_appliance:8.0.6:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance8.0.7cpe:2.3:a:cisco:web_security_virtual_appliance:8.0.7:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance8.0_basecpe:2.3:a:cisco:web_security_virtual_appliance:8.0_base:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.8

Confidence

High

EPSS

0.002

Percentile

64.8%

Related for CVE-2015-6290