CVE-2016-1356

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
03/03/2016
Last modified:
12/04/2025

Description

Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:firesight_system_software:_6.1.0:*:*:*:*:*:*:*