CVE-2016-6437

A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performance degradation. More Information: CSCva03095. Known Affected Releases: 5.3(5), 6.1(1), 6.2(1). Known Fixed Releases: 5.3(5g)1, 6.2(2.32).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
ciscowide_area_application_services
5.3.1
ciscowide_area_application_services
5.3.3
ciscowide_area_application_services
5.3.5
ciscowide_area_application_services
5.3.5a:a
ciscowide_area_application_services
5.3.5b:b
ciscowide_area_application_services
5.3.5c:c
ciscowide_area_application_services
5.3.5d:d
ciscowide_area_application_services
5.3.5e:e
ciscowide_area_application_services
5.3.5f:f
ciscowide_area_application_services
6.1.0
ciscowide_area_application_services
6.1.1
ciscowide_area_application_services
6.2.1
ciscowide_area_application_services
6.2.1a:a
𝑥
= Vulnerable software versions
Common Weakness Enumeration