CVE-2016-6360: Cisco Email Security Appliance
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233.
Affected products
- Cisco Email Security Appliance: version 9.5.0-000 only; version 9.5.0-201 only; version 9.6.0-000 only; version 9.6.0-042 only; version 9.6.0-051 only; version 9.7.0-125 only
- Cisco Web Security Appliance: version 8.8.0-085 only; version 9.0.0-193 only; version 9.0_base only; version 9.1.0-000 only; version 9.1.0-070 only; version 9.1_base only; …
Published 2016-10-28. Last modified 2026-06-17.