CVE-2015-6418

Severity
4.3MEDIUM
EPSS
0.4%
top 40.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateMay 17

Description

The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake key-exchange data, aka Bug ID CSCus15224.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages7 packages

NVDcisco/sa5202.2.07
NVDcisco/sa5402.2.07
NVDcisco/sa520w2.2.07
NVDcisco/rv016_multi-wan_vpn_firmware4.0.0.7, 4.0.2.8, 4.0.5.0+2

🔴Vulnerability Details

2
GHSA
GHSA-9rcv-p8fh-p3ch: The random-number generator on Cisco Small Business RV routers 42022-05-17
CVEList
CVE-2015-6418: The random-number generator on Cisco Small Business RV routers 42015-12-13

📋Vendor Advisories

1
Cisco
Cisco Small Business RV Series and SA500 Series Dual WAN VPN Router Generated Key Pair Information Disclosure Vulnerability2015-12-11
CVE-2015-6418 (MEDIUM CVSS 4.3) | The random-number generator on Cisc | cvebase.io