7.5

CVE-2016-1402

The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIdentity Services Engine Software Version1.2.0.899 Updatep1
   CiscoIdentity Services Engine Version-
CiscoIdentity Services Engine Software Version1.2.0.899 Updatep2
   CiscoIdentity Services Engine Version-
CiscoIdentity Services Engine Software Version1.2.0.899 Updatep3
   CiscoIdentity Services Engine Version-
CiscoIdentity Services Engine Software Version1.2.0.899 Updatep4
   CiscoIdentity Services Engine Version-
CiscoIdentity Services Engine Software Version1.2.0.899 Updatep5
   CiscoIdentity Services Engine Version-
CiscoIdentity Services Engine Software Version1.2.0.899 Updatep6
   CiscoIdentity Services Engine Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.09% 0.771
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.