Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-6360


A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233.


Published

2016-10-28T10:59:10.213

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco email_security_appliance 9.5.0-000 Yes
Application cisco email_security_appliance 9.5.0-201 Yes
Application cisco email_security_appliance 9.6.0-000 Yes
Application cisco email_security_appliance 9.6.0-042 Yes
Application cisco email_security_appliance 9.6.0-051 Yes
Application cisco email_security_appliance 9.7.0-125 Yes
Application cisco web_security_appliance 8.8.0-085 Yes
Application cisco web_security_appliance 9.0.0-193 Yes
Application cisco web_security_appliance 9.0_base Yes
Application cisco web_security_appliance 9.1.0-000 Yes
Application cisco web_security_appliance 9.1.0-070 Yes
Application cisco web_security_appliance 9.1_base Yes
Application cisco web_security_appliance 9.5.0-235 Yes
Application cisco web_security_appliance 9.5.0-284 Yes
Application cisco web_security_appliance 9.5.0-444 Yes
Application cisco web_security_appliance 9.5_base Yes

References