CVE-2015-6321 - CVE House
Back to Database
Status published High CVE-2015-6321

Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023,...

Vulnerability Description

Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before 8.0.8-113 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug IDs CSCus79774, CSCus79777, and CSCzv95795.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-6321

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

web security appliance, content security management appliance, email security appliance
Vulnerable Versions:
5.6.0-623, 6.0.0-000, 7.5.0-000, 7.5.0-825, 7.5.1-000, 7.5.2-000, 7.7.0-000, 7.7.1-000, 8.0.0-000, 8.5.0.000, 7.8.0-328, 7.8.1-001, 7.9.0-201, 7.9.2-116, 8.0.1-031, 8.1.0-001, 8.1.1-033, 8.1.2-000, 8.2.0-238, 8.3.0-350, 8.3.5-061, 8.3.6-014, 8.3.7-010, 8.4.0-150, 9.0.0-073, 9.1.0-004, 7.6.1-000, 7.6.3-000, 7.8.0-311, 8.5.6-052, 8.6.0-011, 8.9.1-000, 8.9.2-032, 9.0.0-212, 9.0.5-000, 9.1.0-011, 9.4.4-000, 9.5.0-000

Timeline

Official Publish: November 6th, 2015
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.