MEDIUM · 5.9

CVE-2015-6358

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man...

Vulnerability Description

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.

CVSS Score

5.9

MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoRv320 Firmware<= 1.3.1.10
CiscoRv320-
CiscoRv325 Firmware<= 1.3.1.10
CiscoRv325-
CiscoRvs4000 Firmware<= 2.0.3.4
CiscoRvs4000-
CiscoWrv210 Firmware<= 2.0.1.5
CiscoWrv210-
CiscoWap4410N Firmware<= 2.0.7.8
CiscoWap4410N-
CiscoWrv200 Firmware1.0.39
CiscoWrv200-
CiscoWrvs4400N Firmware<= 2.0.2.2
CiscoWrvs4400N-
CiscoWap200 Firmware<= 2.0.6.0
CiscoWap200-
CiscoWvc2300 Firmware<= 1.1.2.6
CiscoWvc2300-
CiscoPvc2300 Firmware<= 1.1.2.6
CiscoPvc2300-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-6358?

CVE-2015-6358 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man...

How severe is CVE-2015-6358?

CVE-2015-6358 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-6358?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Rv320 Firmware, Cisco Rv320, Cisco Rv325 Firmware, Cisco Rv325, Cisco Rvs4000 Firmware.