CVE Vulnerabilities

CVE-2016-1356

Published: Mar 03, 2016 | Modified: Dec 03, 2016
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.

Affected Software

Name Vendor Start Version End Version
Firesight_system_software Cisco _6.1.0 (including) _6.1.0 (including)

References