CVE-2019-1672
MEDIUMCisco Web Security Appliance - Unauthenticated Policy Bypass via SSL Traffic Handling
Title source: llmDescription
A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of SSL-encrypted traffic when Decrypt for End-User Notification is disabled in the configuration. An attacker could exploit this vulnerability by sending a SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured drop policy to block specific SSL connections. Releases 10.1.x and 10.5.x are affected.
References (2)
Core 2
Core References
Third Party Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190206-wsa-bypass
Third Party Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/106904
Scores
CVSS v3
5.8
EPSS
0.0164
EPSS Percentile
73.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (3)
cisco/web_security_appliance
10.1.0-204
cisco/web_security_appliance
10.5.2-072
cisco/web_security_appliance
11.5.1-fcs-115
Published
Feb 08, 2019
Tracked Since
Feb 18, 2026