CVE-2016-1402
Last modified
CVE-2016-1402 is a vulnerability of currently unknown severity. The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.. EPSS estimates a 1.99% chance of exploitation in the next 30 days.
Description
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Cisco | Identity Services Engine Software | 1.2.0.899 | P1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1402?
How severe is CVE-2016-1402?
How do I fix CVE-2016-1402?
Are you affected by CVE-2016-1402?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
