7.5

CVE-2016-6407

Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219.

Data is provided by the National Vulnerability Database (NVD)
CiscoWeb Security Appliance Version5.6.0-623
CiscoWeb Security Appliance Version6.0.0-000
CiscoWeb Security Appliance Version7.1.0
CiscoWeb Security Appliance Version7.1.1
CiscoWeb Security Appliance Version7.1.2
CiscoWeb Security Appliance Version7.1.3
CiscoWeb Security Appliance Version7.1.4
CiscoWeb Security Appliance Version7.5.0-000
CiscoWeb Security Appliance Version7.5.0-825
CiscoWeb Security Appliance Version7.5.1-000
CiscoWeb Security Appliance Version7.5.2-000
CiscoWeb Security Appliance Version7.5.2-hp2-303
CiscoWeb Security Appliance Version7.7.0-000
CiscoWeb Security Appliance Version7.7.0-608
CiscoWeb Security Appliance Version7.7.1-000
CiscoWeb Security Appliance Version7.7.5-835
CiscoWeb Security Appliance Version8.0.0-000
CiscoWeb Security Appliance Version8.0.5
CiscoWeb Security Appliance Version8.0.6
CiscoWeb Security Appliance Version8.0.6-078
CiscoWeb Security Appliance Version8.0.6-119
CiscoWeb Security Appliance Version8.0.7
CiscoWeb Security Appliance Version8.0.7-142
CiscoWeb Security Appliance Version8.0.8-mr-113
CiscoWeb Security Appliance Version8.5.0-497
CiscoWeb Security Appliance Version8.5.0.000
CiscoWeb Security Appliance Version8.5.1-021
CiscoWeb Security Appliance Version8.5.2-024
CiscoWeb Security Appliance Version8.5.2-027
CiscoWeb Security Appliance Version8.5.3-055
CiscoWeb Security Appliance Version8.8.0-000
CiscoWeb Security Appliance Version8.8.0-085
CiscoWeb Security Appliance Version9.0.0-193
CiscoWeb Security Appliance Version9.0_base
CiscoWeb Security Appliance Version9.1.0-000
CiscoWeb Security Appliance Version9.1.0-070
CiscoWeb Security Appliance Version9.1_base
CiscoWeb Security Appliance Version9.5.0-235
CiscoWeb Security Appliance Version9.5.0-284
CiscoWeb Security Appliance Version9.5.0-444
CiscoWeb Security Appliance Version9.5_base
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.75% 0.723
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P