← Back

CVE-2019-1672

nvd nist
Published: Feb 8, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of SSL-encrypted traffic when Decrypt for End-User Notification is disabled in the configuration. An attacker could exploit this vulnerability by sending a SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured drop policy to block specific SSL connections. Releases 10.1.x and 10.5.x are affected.

Affected (3)

1 product
Web Security Appliance
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 10.1.0-204
Version 10.5.2-072
Version 11.5.1-fcs-115

References (4)

Source: psirt@cisco.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.