Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.

Project Subscriptions

Vendors Products
Pvc2300 Subscribe
Pvc2300 Firmware Subscribe
Rtp300 Firmware Subscribe
Rv120w Firmware Subscribe
Rv180 Firmware Subscribe
Rv180w Firmware Subscribe
Rv220w Firmware Subscribe
Rv315w Firmware Subscribe
Rv320 Firmware Subscribe
Rv325 Firmware Subscribe
Rvs4000 Subscribe
Rvs4000 Firmware Subscribe
Spa400 Firmware Subscribe
Srp520-u Subscribe
Srp520-u Firmware Subscribe
Srp520 Firmware Subscribe
Srw224p Subscribe
Srw224p Firmware Subscribe
Wap2000 Subscribe
Wap2000 Firmware Subscribe
Wap200 Firmware Subscribe
Wap4400n Subscribe
Wap4400n Firmware Subscribe
Wap4410n Subscribe
Wap4410n Firmware Subscribe
Wet200 Firmware Subscribe
Wrp500 Firmware Subscribe
Wrv200 Firmware Subscribe
Wrv210 Firmware Subscribe
Wrvs4400n Subscribe
Wrvs4400n Firmware Subscribe
Wvc2300 Subscribe
Wvc2300 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2015-6300 Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-08-06T07:22:20.764Z

Reserved: 2015-08-17T00:00:00.000Z

Link: CVE-2015-6358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-10-12T15:29:00.217

Modified: 2025-04-20T01:37:25.860

Link: CVE-2015-6358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses