CVE-2015-6358
published 2017-10-12CVE-2015-6358: Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.31%
67.6th percentile
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products_confidential | — | — |
| cisco | pvc2300_firmware | <= 1.1.2.6 | — |
| cisco | rtp300_firmware | <= 3.1.24 | — |
| cisco | rv120w_firmware | <= 1.0.5.9 | — |
| cisco | rv180_firmware | <= 1.0.5.4 | — |
| cisco | rv180w_firmware | <= 1.0.5.4 | — |
| cisco | rv220w_firmware | <= 1.0.4.17 | — |
| cisco | rv315w_firmware | <= 1.01.03 | — |
| cisco | rv320_firmware | <= 1.3.1.10 | — |
| cisco | rv325_firmware | <= 1.3.1.10 | — |
| cisco | rvs4000_firmware | <= 2.0.3.4 | — |
| cisco | spa400_firmware | <= 1.1.2.2 | — |
| cisco | srp520-u_firmware | <= 1.2.6 | — |
| cisco | srp520_firmware | <= 1.01.29 | — |
| cisco | srw224p_firmware | <= 2.0.2.4 | — |
| cisco | wap2000_firmware | <= 2.0.8.0 | — |
| cisco | wap200_firmware | <= 2.0.6.0 | — |
| cisco | wap4400n_firmware | <= - | — |
| cisco | wap4410n_firmware | <= 2.0.7.8 | — |
| cisco | wet200_firmware | <= 2.0.8.0 | — |
| cisco | wrp500_firmware | <= 1.0.1.002 | — |
| cisco | wrv200_firmware | — | — |
| cisco | wrv210_firmware | <= 2.0.1.5 | — |
| cisco | wrvs4400n_firmware | <= 2.0.2.2 | — |
| cisco | wvc2300_firmware | <= 1.1.2.6 | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco Products Confidential Information Decryption Man-in-the-Middle Vulnerability
vendor_cisco·2015-11-25·CVSS 5.0
CVE-2015-6358 [MEDIUM] CWE-310 Multiple Cisco Products Confidential Information Decryption Man-in-the-Middle Vulnerability
Multiple Cisco Products Confidential Information Decryption Man-in-the-Middle Vulnerability
A vulnerability in the cryptographic implementation of multiple Cisco products could allow an unauthenticated, remote attacker to make use of hard-coded certificate and keys embedded within the firmware of the affected device.
The vulnerability is due to the lack of unique key and certificate generation within affected appliances. An attacker could exploit this vulnerability by using the static information to conduct man-in-the-middle attacks to decrypt confidential information on user connections.
This is an attack on the client attempting to access the device and does not compromise the device itself. To exploit the issue, an attacker needs not only the public and private key pair, but also a p
Cisco
Multiple Cisco Products Confidential Information Decryption Man-in-the-Middle Vulnerability
vendor_cisco
CVE-2015-6358 Multiple Cisco Products Confidential Information Decryption Man-in-the-Middle Vulnerability
CVE-2015-6358: Multiple Cisco Products Confidential Information Decryption Man-in-the-Middle Vulnerability
A vulnerability in the cryptographic implementation of multiple Cisco products could allow an unauthenticated, remote attacker to make use of hard-coded certificate and keys embedded within the firmware of the affected device. The vulnerability is due to the lack of unique key and certificate generation within affected appliances. An attacker could exploit this vulnerability by using the static information to conduct man-in-the-middle attacks to decrypt confidential information on user connections. This is an attack on the client attempting to access the device and does not compromise the device itself. To exploit the issue, an attacker needs not only the public and private key pair,
GHSA
GHSA-vf47-j2qm-x7p4: Multiple Cisco embedded devices use hardcoded X
ghsa_unreviewed·2022-05-17
CVE-2015-6358 [MEDIUM] CWE-295 GHSA-vf47-j2qm-x7p4: Multiple Cisco embedded devices use hardcoded X
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151125-cihttp://www.kb.cert.org/vuls/id/566724http://www.securityfocus.com/bid/78047http://www.securitytracker.com/id/1034255http://www.securitytracker.com/id/1034256http://www.securitytracker.com/id/1034257http://www.securitytracker.com/id/1034258http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151125-cihttp://www.kb.cert.org/vuls/id/566724http://www.securityfocus.com/bid/78047http://www.securitytracker.com/id/1034255http://www.securitytracker.com/id/1034256http://www.securitytracker.com/id/1034257http://www.securitytracker.com/id/1034258
2017-10-12
Published