CVE-2003-1096
The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute...
Affects 1 product across 1 vendor.
The Cisco LEAP challenge/response authentication mechanism is vulnerable to dictionary attacks, allowing remote attackers to potentially gain unauthorized access through brute force password guessing.
BSID: BS-2003-GLOBAL-156888-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2003-1096?
What is the CVSS score for CVE-2003-1096?
Is CVE-2003-1096 actively exploited?
How do I remediate CVE-2003-1096?
What systems are affected by CVE-2003-1096?
| CVE ID | CVE-2003-1096 |
|---|---|
| BSID | BS-2003-GLOBAL-156888-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2003-12-31 |
| Last Modified | 2026-04-16 |
| ICS Relevance | 55% |
| Domains | |
| Source | NVD |
The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.
Source: NIST NVD / MITRE CVE Database
The vulnerability lies in the way passwords are handled in the Cisco LEAP authentication process, making it susceptible to dictionary attacks where attackers can systematically try different password combinations to gain access.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Cisco | Leap | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →