7.5
CVE-2016-1402
- EPSS 1.99%
- Veröffentlicht 21.05.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p1
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p2
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p3
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p4
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p5
Cisco ≫ Identity Services Engine Software Version 1.2.0.899 Update p6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.99% | 0.781 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160517-ise
http://www.securitytracker.com/id/1035946