|
Description
|
|
A vulnerability has been reported in Cisco Web Security Appliance, which can be exploited by malicious people to bypass certain security restrictions.
The vulnerability is caused due to the proxy engine not properly handling HTTP methods and can be exploited to bypass the proxied network traffic protection by sending a specially crafted HTTP CONNECT method.
The vulnerability is reported in version 8.5.0-scylla-805.
|
|
|
|
|
|
Vulnerable Products
|
|
Vulnerable OS: Cisco Web Security Appliance 8.xVulnerable Software:
|
|
|
|
|
|
Solution
|
|
No official solution is currently available.
|
|
|
|
|
|
CVE
|
|
CVE-2015-0628
|
|
|
|
|
|
References
|
|
Cisco (CSCus79174):
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0628
http://tools.cisco.com/security/center/viewAlert.x?alertId=37533
|
|
|
|
|
|
Vulnerability Manager Detection
|
|
No
|
|
|
|
|
|
IPS Protection
|
|
|
|
|
|
|