CVE-2016-1296

The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.
Severity
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Atk. Vector
NETWORK
Atk. Complexity
LOW
Priv. Required
NONE
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
ciscoweb_security_appliance
8.5.3-055
ciscoweb_security_appliance
9.1.0-000
ciscoweb_security_appliance
9.5.0-235
𝑥
= Vulnerable software versions
Common Weakness Enumeration