PT-2016-2115 · Cisco · Cisco Identity Service Engine

Publicado

2016-05-21

·

Atualizado

2016-12-01

·

CVE-2016-1402

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Identity Service Engine versions prior to 1.2.0.899 patch 7
Description The issue is related to the Active Directory integration component when AD group-membership authorization is enabled. It allows remote attackers to cause a denial of service, specifically an authentication outage, via a crafted Password Authentication Protocol (PAP) authentication request.
Recommendations For versions prior to 1.2.0.899 patch 7, apply patch 7 to resolve the issue. As a temporary workaround, consider disabling AD group-membership authorization until the patch is applied. Restrict access to the Active Directory integration component to minimize the risk of exploitation. Avoid using the PAP authentication protocol in the affected component until the issue is resolved.

Correção

Improper Authentication

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01468
CVE-2016-1402

Produtos afetados

Cisco Identity Service Engine