CVE-2016-6416

The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz86065.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
ciscocontent_security_management_appliance
9.1.0
ciscocontent_security_management_appliance
9.1.0-004
ciscocontent_security_management_appliance
9.1.0-031
ciscocontent_security_management_appliance
9.1.0-033
ciscocontent_security_management_appliance
9.1.0-103
ciscocontent_security_management_appliance
9.5.0
ciscocontent_security_management_appliance
9.6.0
ciscoemail_security_appliance
9.6.0-000
ciscoemail_security_appliance
9.6.0-042
ciscoemail_security_appliance
9.6.0-051
ciscoemail_security_appliance
9.7.1-066
ciscoemail_security_appliance
9.9.6-026
ciscoemail_security_appliance
9.9_base:_base
ciscoweb_security_appliance
9.0.0-162
ciscoweb_security_appliance
9.1.0-000
ciscoweb_security_appliance
9.1.0-070
ciscoweb_security_appliance
9.1_base:_base
ciscoweb_security_appliance
9.5.0-235
ciscoweb_security_appliance
9.5.0-284
ciscoweb_security_appliance
9.5.0-444
ciscoweb_security_appliance
9.5_base:_base
𝑥
= Vulnerable software versions