VYPR
Unrated severityNVD Advisory· Published Mar 4, 2020· Updated Nov 15, 2024

Cisco ESA, Cisco WSA, and Cisco SMA GUI Denial of Service Vulnerability

CVE-2020-3164

Description

Unauthenticated remote attacker can cause high CPU usage on Cisco ESA, WSA, and SMA via malformed HTTP request to web-based management interface, leading to DoS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated remote attacker can cause high CPU usage on Cisco ESA, WSA, and SMA via malformed HTTP request to web-based management interface, leading to DoS.

Vulnerability

The vulnerability resides in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA). It is due to improper validation of specific HTTP request headers. Affected versions: Cisco ESA and Cisco Cloud Email Security Release 13.0.0-392 and earlier; Cisco WSA Release 12.0.1-268 and earlier; Cisco SMA releases earlier than 13.6.0. [1]

Exploitation

An unauthenticated remote attacker can exploit this vulnerability by sending a malformed HTTP request to an affected device. No authentication or user interaction is required. The malformed request triggers a prolonged status of high CPU utilization relative to the GUI process(es). [1]

Impact

Successful exploitation results in a denial of service (DoS) condition where the device's response time and overall performance are degraded due to high CPU usage. The device remains operative but experiences significant performance degradation. [1]

Mitigation

Cisco has released fixed software versions to address this vulnerability. No workarounds are available. For ESA, upgrade to 13.0.0-392 or later; for WSA, upgrade to 12.0.1-268 or later; for SMA, upgrade to 13.6.0 or later. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.