Lucene search

K
cveCiscoCVE-2017-12250
HistorySep 21, 2017 - 5:29 a.m.

CVE-2017-12250

2017-09-2105:29:00
CWE-20
CWE-399
cisco
web.nvd.nist.gov
40
cisco
waas
http
vulnerability
remote attacker
denial of service
input validation
exploit
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

5.3

Confidence

High

EPSS

0.002

Percentile

51.4%

A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related process to restart, causing a partial denial of service (DoS) condition. The vulnerability is due to lack of input validation of user-supplied input parameters within an HTTP request. An attacker could exploit this vulnerability by sending a crafted HTTP request through the targeted device. An exploit could allow the attacker to cause a DoS condition due to a process unexpectedly restarting. The WAAS could drop traffic during the brief time the process is restarting. Cisco Bug IDs: CSCvc63048.

Affected configurations

Nvd
Node
ciscowide_area_application_servicesMatch6.2\(3a\)
VendorProductVersionCPE
ciscowide_area_application_services6.2(3a)cpe:2.3:a:cisco:wide_area_application_services:6.2\(3a\):*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco Wide Area Application Services",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco Wide Area Application Services"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

5.3

Confidence

High

EPSS

0.002

Percentile

51.4%

Related for CVE-2017-12250