CVE-2015-6358
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of…
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- cisco/rv320 firmware · cisco/rv325 firmware · cisco/rvs4000 firmware · cisco/wrv210 firmware · cisco/wap4410n firmware · cisco/wrv200 firmware · cisco/wrvs4400n firmware · cisco/wap200 firmware · cisco/wvc2300 firmware · cisco/pvc2300 firmware · cisco/srw224p firmware · cisco/wet200 firmware · cisco/wap2000 firmware · cisco/wap4400n firmware · cisco/rv120w firmware · cisco/rv180 firmware · cisco/rv180w firmware · cisco/rv315w firmware · cisco/srp520 firmware · cisco/srp520-u firmware · +4 more
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151125-ciIssue Tracking, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/566724Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/78047Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034255Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034256Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034257Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034258Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151125-ciIssue Tracking, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/566724Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/78047Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034255Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034256Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034257Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034258Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.