Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j66f-ff6x-m5fc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.

Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.

EPSS

Процентиль: 46%
0.00236
Низкий

3.7 Low

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 3.7
nvd
почти 10 лет назад

Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.

EPSS

Процентиль: 46%
0.00236
Низкий

3.7 Low

CVSS3

Дефекты

CWE-287