Input validation error in Cisco AsyncOS for Secure Web Appliance - CVE-2019-1886

 

Input validation error in Cisco AsyncOS for Secure Web Appliance - CVE-2019-1886

Published: July 8, 2019


Vulnerability identifier: #VU19021
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1886
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

The vulnerability exist due to insufficient validation of Secure Sockets Layer (SSL) server certificates in the HTTPS decryption feature. A remote attacker can install a malformed certificate in a web server, send a request to it through the Cisco WSA and cause an unexpected restart of the proxy process on an affected device.


Affected software

Cisco AsyncOS for Secure Web Appliance

How to mitigate CVE-2019-1886

Install update from vendor's website.

Cisco AsyncOS for Secure Web Appliance - addressed in versions 10.5.5 005, 11.5.2 020

External References

Related Security Bulletins