CVE-2015-6386: Cisco Web Security Appliance

Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.

The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer, aka Bug ID CSCut94150.

Affected products

  • Cisco Web Security Appliance: version 8.0.7-142 only; version 8.5.1-021 only

Published 2015-12-01. Last modified 2026-06-17.