CVE-2016-1382: Cisco Web Security Appliance (wsa)
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allows remote attackers to cause a denial of service (proxy-process reload) via a crafted request, aka Bug ID CSCuu02529.
Affected products
- Cisco Web Security Appliance (wsa): version 5.6.0-623 only; version 6.0.0-000 only; version 7.1.0 only; version 7.1.1 only; version 7.1.2 only; version 7.1.3 only; …
Published 2016-05-25. Last modified 2026-06-17.