7.5

CVE-2016-1402

The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p1
   Cisco ≫ Identity Services Engine Version -
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p2
   Cisco ≫ Identity Services Engine Version -
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p3
   Cisco ≫ Identity Services Engine Version -
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p4
   Cisco ≫ Identity Services Engine Version -
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p5
   Cisco ≫ Identity Services Engine Version -
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p6
   Cisco ≫ Identity Services Engine Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.99% 0.781
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160517-ise
Vendor Advisory
http://www.securitytracker.com/id/1035946