7.5
CVSSv3

CVE-2016-1402

Published: 21/05/2016 Updated: 01/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) prior to 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote malicious users to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity_services_engine_software 1.2.0.899