CVE-2016-6416

EUVD-2016-7339
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz86065.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
ciscocontent_security_management_appliance
9.1.0
ciscocontent_security_management_appliance
9.1.0-004
ciscocontent_security_management_appliance
9.1.0-031
ciscocontent_security_management_appliance
9.1.0-033
ciscocontent_security_management_appliance
9.1.0-103
ciscocontent_security_management_appliance
9.5.0
ciscocontent_security_management_appliance
9.6.0
ciscoemail_security_appliance
9.6.0-000
ciscoemail_security_appliance
9.6.0-042
ciscoemail_security_appliance
9.6.0-051
ciscoemail_security_appliance
9.7.1-066
ciscoemail_security_appliance
9.9.6-026
ciscoemail_security_appliance
9.9_base:_base
ciscoweb_security_appliance
9.0.0-162
ciscoweb_security_appliance
9.1.0-000
ciscoweb_security_appliance
9.1.0-070
ciscoweb_security_appliance
9.1_base:_base
ciscoweb_security_appliance
9.5.0-235
ciscoweb_security_appliance
9.5.0-284
ciscoweb_security_appliance
9.5.0-444
ciscoweb_security_appliance
9.5_base:_base
𝑥
= Vulnerable software versions