Cisco Web Security Appliance Drop Decrypt Policy Bypass Vulnerability
The vulnerability is due to incomplete input validation of HTTP headers. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to connect to a website that should be blocked.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2gCAopZ
The vulnerability is due to incomplete input validation of HTTP headers. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to connect to a website that should be blocked.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2gCAopZ
Security Impact Rating: Medium
CVE: CVE-2016-9212
from Cisco Security Advisory http://ift.tt/2gCAopZ