CVE-2019-1886 is a high-severity denial-of-service (DoS) vulnerability affecting Cisco Web Security Appliance (WSA) and AsyncOS, stemming from insufficient validation of SSL server certificates during HTTPS decryption. An unauthenticated, remote attacker can exploit this by presenting a specially crafted, malformed certificate to the WSA, causing the proxy process to unexpectedly restart. While the CVSS score is 8.6, indicating high severity with network attack vector and low complexity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.5, < 10.5.5-005CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
>= 11.5, < 11.5.2-020CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
10.5.2-072CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:10.5.2-072:*:*:*:*:*:*:* | ||
10.5.3-025CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:10.5.3-025:*:*:*:*:*:*:* | ||
11.7.0-fcs-334CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:11.7.0-fcs-334:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.