Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2019-1886— Cisco Web Security Appliance HTTPS Certificate Denial of Service Vulnerability

Quick assessment

Affected
Cisco Cisco Web Security Appliance (WSA)
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco Web Security Appliance(WSA)是美国思科(Cisco)公司的一款Web安全设备。该设备提供基于SaaS的访问控制、实时网络报告和追踪、制定安全策略等功能。AsyncOS Software是使用在其中的一套操作系统。 Cisco WSA中的AsyncOS Software的HTTPS解密功能存在输入验证错误漏洞,该漏洞源于程序没有充分地验证SSL服务器的证书。远程攻击者可通过安装畸形的证书利用该漏洞造成拒绝服务。

AI Predicted 7.5 Difficulty: Easy EPSS 1.35% · P69
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-1886

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Web Security Appliance HTTPS Certificate Denial of Service Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this vulnerability by installing a malformed certificate in a web server and sending a request to it through the Cisco WSA. A successful exploit could allow the attacker to cause an unexpected restart of the proxy process on an affected device.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco Web Security Appliance AsyncOS Software 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Web Security Appliance(WSA)是美国思科(Cisco)公司的一款Web安全设备。该设备提供基于SaaS的访问控制、实时网络报告和追踪、制定安全策略等功能。AsyncOS Software是使用在其中的一套操作系统。 Cisco WSA中的AsyncOS Software的HTTPS解密功能存在输入验证错误漏洞,该漏洞源于程序没有充分地验证SSL服务器的证书。远程攻击者可通过安装畸形的证书利用该漏洞造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco Cisco Web Security Appliance (WSA) unspecified ~ 10.5.5-005 -

II. Public POCs for CVE-2019-1886

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-1886

登录查看更多情报信息。

Vendor Advisories for CVE-2019-1886 (2)

Same Patch Batch · Cisco · 2019-07-04 · 5 CVEs total

CVE-2019-1890 Cisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized A
CVE-2019-1889 Cisco Application Policy Infrastructure Controller REST API Privilege Escalation Vulnerabi
CVE-2019-1855 Cisco Jabber for Windows DLL Preloading Vulnerability
CVE-2019-1884 Cisco Web Security Appliance Web Proxy Denial of Service Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2019-1886

No comments yet


Leave a comment