CVE-2016-1380 describes a denial-of-service vulnerability in Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted HTTP POST request, causing the proxy process to hang. This vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on availability. While no public exploit code or active exploitation has been observed, it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.0-000CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:8.0.0-000:*:*:*:*:*:*:* | ||
8.0.5CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:8.0.5:*:*:*:*:*:*:* | ||
8.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:8.0.6:*:*:*:*:*:*:* | ||
8.0.6-078CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:8.0.6-078:*:*:*:*:*:*:* | ||
8.0.6-119CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:8.0.6-119:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.