Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.
References
Configurations
Information
Published : 2016-03-03 14:59
Updated : 2016-12-02 19:20
NVD link : CVE-2016-1356
Mitre link : CVE-2016-1356
JSON object : View
Products Affected
cisco
- firesight_system_software