← Back

CVE-2019-1884

nvd nist
Published: Jul 4, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in HTTP/HTTPS requests sent through an affected device. A successful attacker could exploit this vulnerability by sending a malicious HTTP/HTTPS request through an affected device. An exploit could allow the attacker to force the device to stop processing traffic, resulting in a DoS condition.

Affected (7)

2 products
Asyncos
Web Security Appliance
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
From 10.1 to 10.5.5-005
From 11.5 to 11.5.2-020
From 11.7 to 11.7.0-407
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 10.1.4-017
Version 10.5.2-072
Version 11.5.1-fcs-125
Version 11.7.0-256

Timeline

No history available yet.