CVE-2016-1402: Buffer Overflow
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1402?
CVE-2016-1402 has been assigned a severity rating that indicates it can cause a denial of service in affected Cisco Identity Service Engine versions.
How do I fix CVE-2016-1402?
To fix CVE-2016-1402, upgrade to Cisco Identity Service Engine version 1.2.0.899 patch 7 or later.
What is the impact of CVE-2016-1402?
The impact of CVE-2016-1402 is an authentication outage that could compromise user access to Active Directory-integrated services.
Which software versions are affected by CVE-2016-1402?
CVE-2016-1402 affects Cisco Identity Service Engine versions prior to 1.2.0.899 patch 7.
Who can exploit CVE-2016-1402?
CVE-2016-1402 can be exploited by remote attackers who leverage crafted Password Authentication Protocol (PAP) authentication requests.