CVE-2015-6421: Cisco Wide Area Application Services

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) devices 5.x before 5.3.5d and 5.4 and 5.5 before 5.5.3 allows remote attackers to cause a denial of service (resource consumption and device reload) via crafted network traffic, aka Bug ID CSCus85330.

Affected products

  • Cisco Wide Area Application Services: version 5.1.1 only; version 5.1.1a only; version 5.1.1b only; version 5.1.1c only; version 5.1.1d only; version 5.2.1 only; …

Published 2016-01-27. Last modified 2026-06-17.