High severity7.5NVD Advisory· Published Jan 20, 2016· Updated May 6, 2026
CVE-2016-1296
CVE-2016-1296
Description
The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.
Affected products
3cpe:2.3:a:cisco:web_security_appliance:8.5.3-055:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cisco:web_security_appliance:8.5.3-055:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:web_security_appliance:9.1.0-000:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:web_security_appliance:9.5.0-235:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160119-wsanvdVendor Advisory
- www.securitytracker.com/id/1034763nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.