SB2019070808 - Denial of service in Cisco Web Security Appliance
Published: July 8, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2019-1886)
The vulnerability allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability exist due to insufficient validation of Secure Sockets Layer (SSL) server certificates in the HTTPS decryption feature. A remote attacker can install a malformed certificate in a web server, send a request to it through the Cisco WSA and cause an unexpected restart of the proxy process on an affected device.
Remediation
Install update from vendor's website.