← Back

CVE-2019-15956

nvd nist
Published: Nov 26, 2019Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could have a twofold impact: the attacker could either change the administrator password, gaining privileged access, or reset the network configuration details, causing a denial of service (DoS) condition. In both scenarios, manual intervention is required to restore normal operations.

Affected (6)

2 products
Asyncos
Web Security Appliance
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
From 10.1 to 10.1.5-004
From 10.5 to 11.5.3-016
From 11.7 to 11.7.1-006
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 10.5.2-072
Version 11.5.1-fcs-125
Version 11.7.0-fcs-418

Timeline

No history available yet.