CVE-2016-1381: Cisco Web Security Appliance

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.

Affected products

  • Cisco Web Security Appliance: version 8.5.0-497 only; version 8.5.0.000 only; version 8.5.1-021 only; version 8.5.2-024 only; version 8.5.2-027 only; version 8.5.3-055 only; …

Published 2016-05-25. Last modified 2026-06-17.