Description
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
Published: 2017-10-12
Score: 5.9 Medium
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2015-6300 Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
History

No history.

Subscriptions

Cisco Pvc2300 Pvc2300 Firmware Rtp300 Rtp300 Firmware Rv120w Rv120w Firmware Rv180 Rv180 Firmware Rv180w Rv180w Firmware Rv220w Rv220w Firmware Rv315w Rv315w Firmware Rv320 Rv320 Firmware Rv325 Rv325 Firmware Rvs4000 Rvs4000 Firmware Spa400 Spa400 Firmware Srp520 Srp520-u Srp520-u Firmware Srp520 Firmware Srw224p Srw224p Firmware Wap200 Wap2000 Wap2000 Firmware Wap200 Firmware Wap4400n Wap4400n Firmware Wap4410n Wap4410n Firmware Wet200 Wet200 Firmware Wrp500 Wrp500 Firmware Wrv200 Wrv200 Firmware Wrv210 Wrv210 Firmware Wrvs4400n Wrvs4400n Firmware Wvc2300 Wvc2300 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-08-06T07:22:20.764Z

Reserved: 2015-08-17T00:00:00.000Z

Link: CVE-2015-6358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-10-12T15:29:00.217

Modified: 2025-04-20T01:37:25.860

Link: CVE-2015-6358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses