CVE-2015-4217: Infoleak
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH host keys across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a private key from another installation, aka Bug IDs CSCus29681, CSCuu95676, and CSCuu96601.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4217?
CVE-2015-4217 is classified as a high severity vulnerability due to the risk of unauthorized remote access.
How do I fix CVE-2015-4217?
To fix CVE-2015-4217, you should update your Cisco Web Security Virtual Appliance, Email Security Virtual Appliance, or Security Management Virtual Appliance to a version that addresses this vulnerability.
What systems are affected by CVE-2015-4217?
CVE-2015-4217 affects several Cisco appliances including versions of Web Security, Email Security, and Content Security Management Virtual Appliances prior to specific updates.
What risk does CVE-2015-4217 pose to my network?
CVE-2015-4217 poses a risk of potential unauthorized access as multiple installations may share the same default SSH host keys.
Are there any workarounds for CVE-2015-4217?
Currently, the best workaround for CVE-2015-4217 is to disable remote support until a patch is applied.