CVE-2016-1381

Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
ciscoweb_security_appliance
8.5.0-497
ciscoweb_security_appliance
8.5.0.000
ciscoweb_security_appliance
8.5.1-021
ciscoweb_security_appliance
8.5.2-024
ciscoweb_security_appliance
8.5.2-027
ciscoweb_security_appliance
8.5.3-055
ciscoweb_security_appliance
9.0.0-193
ciscoweb_security_appliance
9.0_base:_base
ciscoweb_security_appliance
9.1.0-000
ciscoweb_security_appliance
9.1_base:_base
𝑥
= Vulnerable software versions
Common Weakness Enumeration