CVE-2015-6358 - CVE House
Back to Database
Status published Medium CVE-2015-6358

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH...

Vulnerability Description

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-6358

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

rv320 firmware, rv325 firmware, rvs4000 firmware, wrv210 firmware, wap4410n firmware, wrv200 firmware, wrvs4400n firmware, wap200 firmware, wvc2300 firmware, pvc2300 firmware, srw224p firmware, wet200 firmware, wap2000 firmware, wap4400n firmware, rv120w firmware, rv180 firmware, rv180w firmware, rv315w firmware, srp520 firmware, srp520-u firmware, wrp500 firmware, spa400 firmware, rtp300 firmware, rv220w firmware
Vulnerable Versions:
0, 1.0.39

Timeline

Official Publish: October 12th, 2017
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.