CVE-2015-4216: Infoleak
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH root authorized key across different customers' installations, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of a private key from another installation, aka Bug IDs CSCuu95988, CSCuu95994, and CSCuu96630.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4216?
CVE-2015-4216 has a high severity rating due to the use of default SSH root authorized keys in multiple installations.
How do I fix CVE-2015-4216?
To mitigate CVE-2015-4216, users should change the default SSH root authorized key and ensure that all appliances are updated to the latest software version.
What products are affected by CVE-2015-4216?
CVE-2015-4216 affects Cisco Web Security Virtual Appliance, Email Security Virtual Appliance, and Security Management Virtual Appliance before the specified patch date.
What vulnerabilities does CVE-2015-4216 introduce?
CVE-2015-4216 allows unauthorized access to devices due to the common SSH root key across different users, posing a significant security risk.
Is there a way to check if my system is affected by CVE-2015-4216?
Admins can check the device's SSH configuration and compare software versions against Cisco's advisory to identify if they are affected by CVE-2015-4216.