CVE-2016-6437

MEDIUM

Cisco WAAS - DoS

Title source: llm

Description

A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performance degradation. More Information: CSCva03095. Known Affected Releases: 5.3(5), 6.1(1), 6.2(1). Known Fixed Releases: 5.3(5g)1, 6.2(2.32).

Scores

CVSS v3 5.9
EPSS 0.0071
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-399
Status published

Affected Products (14)

cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
cisco/wide_area_application_services
n/a/Cisco Wide Area Application Services (WAAS) before 5.3(5g)1 and 6.x before 6.2(2.32) < Cisco Wide Area Application Services (WAAS) before 5.3(5g)1 and 6.x before 6.2(2.32)

Timeline

Published Oct 27, 2016
Tracked Since Feb 18, 2026