CVE-2015-6290: Cisco Web Security Virtual Appliance

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.

Affected products

  • Cisco Web Security Virtual Appliance: version 8.0.5 only; version 8.0.6 only; version 8.0.7 only; version 8.0_base only

Published 2015-09-14. Last modified 2026-06-17.