CVE-2016-1288 describes a denial-of-service vulnerability affecting the HTTPS Proxy feature in Cisco Web Security Appliance (WSA) devices running AsyncOS versions prior to 8.5.3-051 and 9.x prior to 9.0.0-485. This medium-severity flaw, with a CVSS score of 5.3, allows unauthenticated remote attackers to cause a service outage by sending a malformed HTTPS request, provided they have certain intranet connectivity. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.0-193CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:9.0.0-193:*:*:*:*:*:*:* | ||
8.5.0-497CPE matchmatch criteria | cpe:2.3:o:cisco:web_security_appliance:8.5.0-497:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.