CVE-2015-6287 describes a denial-of-service vulnerability in Cisco Web Security Appliance (WSA) versions 8.0.6-078 and 8.0.6-115. This flaw allows a remote attacker to disrupt service by flooding the appliance with TCP traffic, leading to DNS resolution delays. The vulnerability has a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network with low attack complexity and no authentication required, potentially causing a partial service outage. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered some community discussion and media coverage, highlighting the lack of available patches at the time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.5CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_virtual_appliance:8.0.5:*:*:*:*:*:*:* | ||
8.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_virtual_appliance:8.0.6:*:*:*:*:*:*:* | ||
8.0_baseCPE matchmatch criteria | cpe:2.3:a:cisco:web_security_virtual_appliance:8.0_base:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.