CVE-2016-6360

UnknownEPSS 2.16%

Last modified

CVE-2016-6360 is a vulnerability of currently unknown severity. A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. EPSS estimates a 2.16% chance of exploitation in the next 30 days.

Description

A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233.

Metrics

EPSS Probability
2.16%

79.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoEmail Security Appliance9.5.0-000
CiscoEmail Security Appliance9.5.0-201
CiscoEmail Security Appliance9.6.0-000
CiscoEmail Security Appliance9.6.0-042
CiscoEmail Security Appliance9.6.0-051
CiscoEmail Security Appliance9.7.0-125
CiscoWeb Security Appliance8.8.0-085
CiscoWeb Security Appliance9.0.0-193
CiscoWeb Security Appliance9.0_base
CiscoWeb Security Appliance9.1.0-000
CiscoWeb Security Appliance9.1.0-070
CiscoWeb Security Appliance9.1_base
CiscoWeb Security Appliance9.5.0-235
CiscoWeb Security Appliance9.5.0-284
CiscoWeb Security Appliance9.5.0-444
CiscoWeb Security Appliance9.5_base

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-6360?
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233.
How severe is CVE-2016-6360?
Severity scoring for CVE-2016-6360 is pending analysis. The EPSS model estimates a 2.16% probability of exploitation in the next 30 days.
How do I fix CVE-2016-6360?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-6360?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST