CVE-2003-1096

CRITICAL ⚠ Exploit

The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute...

Affects 1 product across 1 vendor.

BCS8.96
CVSS 2.010.0
EPSS10.5%
Percentile95th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

The Cisco LEAP challenge/response authentication mechanism is vulnerable to dictionary attacks, allowing remote attackers to potentially gain unauthorized access through brute force password guessing.

BSID: BS-2003-GLOBAL-156888-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2003-1096?
The Cisco LEAP challenge/response authentication mechanism is vulnerable to dictionary attacks, allowing remote attackers to potentially gain unauthorized access through brute force password guessing.
What is the CVSS score for CVE-2003-1096?
CVE-2003-1096 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 10.5%.
Is CVE-2003-1096 actively exploited?
Public exploit available for CVE-2003-1096. Exploitation risk elevated.
How do I remediate CVE-2003-1096?
Priority: IMMEDIATE. Advisory: http://www.cisco.com/warp/public/707/cisco-sn-20030802-leap.shtml PSIRT: [email protected]
What systems are affected by CVE-2003-1096?
CVE-2003-1096 affects: Cisco.
Vulnerability Details
CVE IDCVE-2003-1096
BSIDBS-2003-GLOBAL-156888-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2003-12-31
Last Modified2026-04-16
ICS Relevance55%
Domains
NETWORK-INFRA
SourceNVD
Official Description

The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability lies in the way passwords are handled in the Cisco LEAP authentication process, making it susceptible to dictionary attacks where attackers can systematically try different password combinations to gain access.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco Leap
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8249 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Cisco
CVE-2000-1055 10.0 Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote at... CVE-2004-0391 10.0 Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solutio... CVE-2007-5580 10.0 Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.... CVE-2012-5417 10.0 Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properl... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →