7.5
CVE-2016-6360
- EPSS 1.36%
- Published 28.10.2016 10:59:10
- Last modified 12.04.2025 10:46:40
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Email Security Appliance Version9.5.0-000
Cisco ≫ Email Security Appliance Version9.5.0-201
Cisco ≫ Email Security Appliance Version9.6.0-000
Cisco ≫ Email Security Appliance Version9.6.0-042
Cisco ≫ Email Security Appliance Version9.6.0-051
Cisco ≫ Email Security Appliance Version9.7.0-125
Cisco ≫ Web Security Appliance Version8.8.0-085
Cisco ≫ Web Security Appliance Version9.0.0-193
Cisco ≫ Web Security Appliance Version9.0_base
Cisco ≫ Web Security Appliance Version9.1.0-000
Cisco ≫ Web Security Appliance Version9.1.0-070
Cisco ≫ Web Security Appliance Version9.1_base
Cisco ≫ Web Security Appliance Version9.5.0-235
Cisco ≫ Web Security Appliance Version9.5.0-284
Cisco ≫ Web Security Appliance Version9.5.0-444
Cisco ≫ Web Security Appliance Version9.5_base
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.36% | 0.783 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.