5.9

CVE-2015-6358

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoRv320 Firmware Version <= 1.3.1.10
   CiscoRv320 Version-
CiscoRv325 Firmware Version <= 1.3.1.10
   CiscoRv325 Version-
CiscoRvs4000 Firmware Version <= 2.0.3.4
   CiscoRvs4000 Version-
CiscoWrv210 Firmware Version <= 2.0.1.5
   CiscoWrv210 Version-
CiscoWap4410n Firmware Version <= 2.0.7.8
   CiscoWap4410n Version-
CiscoWrv200 Firmware Version1.0.39
   CiscoWrv200 Version-
CiscoWrvs4400n Firmware Version <= 2.0.2.2
   CiscoWrvs4400n Version-
CiscoWap200 Firmware Version <= 2.0.6.0
   CiscoWap200 Version-
CiscoWvc2300 Firmware Version <= 1.1.2.6
   CiscoWvc2300 Version-
CiscoPvc2300 Firmware Version <= 1.1.2.6
   CiscoPvc2300 Version-
CiscoSrw224p Firmware Version <= 2.0.2.4
   CiscoSrw224p Version-
CiscoWet200 Firmware Version <= 2.0.8.0
   CiscoWet200 Version-
CiscoWap2000 Firmware Version <= 2.0.8.0
   CiscoWap2000 Version-
CiscoWap4400n Firmware Version <= -
   CiscoWap4400n Version-
CiscoRv120w Firmware Version <= 1.0.5.9
   CiscoRv120w Version-
CiscoRv180 Firmware Version <= 1.0.5.4
   CiscoRv180 Version-
CiscoRv180w Firmware Version <= 1.0.5.4
   CiscoRv180w Version-
CiscoRv315w Firmware Version <= 1.01.03
   CiscoRv315w Version-
CiscoSrp520 Firmware Version <= 1.01.29
   CiscoSrp520 Version-
CiscoSrp520-u Firmware Version <= 1.2.6
   CiscoSrp520-u Version-
CiscoWrp500 Firmware Version <= 1.0.1.002
   CiscoWrp500 Version-
CiscoSpa400 Firmware Version <= 1.1.2.2
   CiscoSpa400 Version-
CiscoRtp300 Firmware Version <= 3.1.24
   CiscoRtp300 Version-
CiscoRv220w Firmware Version <= 1.0.4.17
   CiscoRv220w Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.97% 0.825
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.