Vulnerability Bulletins

Cisco FireSIGHT System Software Convert Timing Channel Vulnerability

   
Affected software Cisco
 
A vulnerability in credential authentication for valid and invalid username-password pairs for Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to determine a list of valid usernames for an affected device. The vulnerability is due to implementation details of how system credentials are verified by the affected software. An attacker could exploit this vulnerability by using a combination of valid system logins, invalid system logins, and time variability to try to

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-FireSIGHT1?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20FireSIGHT%20System%20Software%20Convert%20Timing%20Channel%20Vu