ZeroHour

CVE-2016-1356

CVSS 3.0
3.7 low
EPSS
<1%p55
Published
()
Modified
Description

Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.

Vendors
cisco
Products
firesight system software
Weakness
CWE-255, CWE-287
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.