4.3
CVSSv2

CVE-2016-1356

Published: 03/03/2016 Updated: 03/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote malicious users to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firesight system software _6.1.0

Vendor Advisories

A vulnerability in credential authentication for valid and invalid username-password pairs for Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to determine a list of valid usernames for an affected device The vulnerability is due to implementation details of how system credentials are verified by the affected soft ...