CVE-2016-1356
published 2016-03-03CVE-2016-1356: Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate…
PriorityP417low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
0.83%
53.5th percentile
Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firesight_system | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FireSIGHT System Software Convert Timing Channel Vulnerability
vendor_cisco·2016-03-02·CVSS 4.3
CVE-2016-1356 [MEDIUM] CWE-255 Cisco FireSIGHT System Software Convert Timing Channel Vulnerability
Cisco FireSIGHT System Software Convert Timing Channel Vulnerability
A vulnerability in credential authentication for valid and invalid username-password pairs for Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to determine a list of valid usernames for an affected device.
The vulnerability is due to implementation details of how system credentials are verified by the affected software. An attacker could exploit this vulnerability by using a combination of valid system logins, invalid system logins, and time variability to try to continuously authenticate to a device. An exploit could allow the attacker to obtain a list of valid system usernames. The list contains valid usernames only. The list does not contain any associated passwords.
Cisco has not rel
Cisco
Cisco FireSIGHT System Software Convert Timing Channel Vulnerability
vendor_cisco
CVE-2016-1356 Cisco FireSIGHT System Software Convert Timing Channel Vulnerability
CVE-2016-1356: Cisco FireSIGHT System Software Convert Timing Channel Vulnerability
A vulnerability in credential authentication for valid and invalid username-password pairs for Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to determine a list of valid usernames for an affected device. The vulnerability is due to implementation
CWE: CWE-255, CWE-255
Bug IDs: CSCuy41615
GHSA
GHSA-j66f-ff6x-m5fc: Cisco FireSIGHT System Software 6
ghsa_unreviewed·2022-05-17
CVE-2016-1356 [MEDIUM] CWE-287 GHSA-j66f-ff6x-m5fc: Cisco FireSIGHT System Software 6
Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-03-03
Published