Wide Area Application Services

Vendor:

First CVE: Jul 21, 2007 · Active for 19 years

20
Total CVEs
More Total CVEs than 95% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Wide Area Application Services over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2007
19 years ago
Most Recent CVE
May 6, 2021
1,908 days ago

CVE Severity & Scoring

Wide Area Application Services20 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local2 (10.0%)
Network11 (55.0%)
Unknown7 (35.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (55.0%)
High2 (10.0%)
Unknown7 (35.0%)
User Interaction
None12 (60.0%)
Unknown7 (35.0%)
Required1 (5.0%)
Privileges Required
Low1 (5.0%)
High1 (5.0%)
None11 (55.0%)
Unknown7 (35.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attack
Aug 1, 201310.028NONO
A vulnerability in SMART-SSL Accelerator functionality for Cisco Wide Area Application Services (WAAS) 6.2.1, 6.2.1a, and 6.2.3a could allow an unauthenticated, remote attacker to
May 3, 20176.824NONO
The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS
Aug 1, 20139.024NONO
cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) devices 5.x before 5.3.5d and 5.4 and 5.5 before 5.5.3 allows
Jan 27, 20167.523NONO
Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers to execute arbitrary code via a
May 26, 20149.323NONO
A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to elevate their privil
Jun 7, 20186.722NONO
A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service
Oct 5, 20176.521NONO
The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module
Jul 21, 20077.821NONO
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthe
Jun 7, 20185.320NONO
A vulnerability in the web-based GUI of Cisco Wide Area Application Services (WAAS) Central Manager could allow an unauthenticated, remote attacker to retrieve completed reports fr
Jul 10, 20175.320NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Wide Area Application Services

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.4\(3b\)15.31.8%00
6.4\(1\)15.32.4%00
6.3\(1\)15.32.2%00
6.2\(3b\)15.31.6%00
6.2\(3a\)25.32.6%00
6.2.3a16.81.7%00
6.2\(3\)35.81.5%00
6.2.1a26.31.7%00
6.2\(1\)15.31.7%00
6.2.126.31.7%00
6.1\(1\)15.31.8%00
6.1.115.91.7%00
6.1.015.91.7%00
6.0\(1\)15.01.5%00
5.5\(7\)15.31.8%00
5.3.5f15.91.7%00
5.3.5e15.91.7%00
5.3.5d15.91.7%00
5.3.5c26.71.8%00
5.3.5b26.71.8%00