CVE-2016-1356: Medium severity cisco firesight system vulnerability
Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1356?
CVE-2016-1356 has a CVSS score indicating a medium severity due to potential exposure to username enumeration attacks.
How do I fix CVE-2016-1356?
To mitigate CVE-2016-1356, update to a patched version of Cisco FireSIGHT System Software that addresses this vulnerability.
What systems are affected by CVE-2016-1356?
CVE-2016-1356 specifically affects Cisco FireSIGHT System Software version 6.1.0.
What type of attack is possible with CVE-2016-1356?
CVE-2016-1356 allows remote attackers to perform username enumeration attacks by exploiting timing discrepancies.
Is there a workaround for CVE-2016-1356?
There is no confirmed workaround for CVE-2016-1356; upgrading to the latest software version is recommended.