CVE-2015-0667: Medium severity Cisco Content Services Switch 11500 Firmware vulnerability
The Management Interface on Cisco Content Services Switch (CSS) 11500 devices 8.20.4.02 and earlier allows remote attackers to bypass intended restrictions on local-network device access via crafted SSH packets, aka Bug ID CSCut14855.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0667?
CVE-2015-0667 is rated as important due to the potential for remote attackers to bypass restrictions on local-network device access.
How do I fix CVE-2015-0667?
To fix CVE-2015-0667, upgrade the Cisco Content Services Switch 11500 to firmware version 8.20.4.03 or later.
What devices are affected by CVE-2015-0667?
CVE-2015-0667 affects Cisco Content Services Switch 11500 devices running firmware version 8.20.4.02 and earlier.
What type of attack is associated with CVE-2015-0667?
CVE-2015-0667 allows remote attackers to conduct unauthorized access through crafted SSH packets.
What is the workaround for CVE-2015-0667 if I cannot upgrade immediately?
Currently, the best workaround for CVE-2015-0667 is to limit SSH access to trusted sources until the firmware can be upgraded.