CVE-2015-6290 describes a denial-of-service vulnerability in Cisco Web Security Appliance (WSA) version 8.0.7. Remote HTTP servers can exploit this flaw by sending crafted responses, leading to excessive memory consumption from stale TCP connections. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial denial of service, but no impact on confidentiality or integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.5CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_virtual_appliance:8.0.5:*:*:*:*:*:*:* | ||
8.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_virtual_appliance:8.0.6:*:*:*:*:*:*:* | ||
8.0.7CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_virtual_appliance:8.0.7:*:*:*:*:*:*:* | ||
8.0_baseCPE matchmatch criteria | cpe:2.3:a:cisco:web_security_virtual_appliance:8.0_base:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.