CVE-2015-6280: Critical severity cisco ios vulnerability
The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before 3.11.4S, 3.12S before 3.12.3S, 3.13S before 3.13.3S, and 3.14S before 3.14.1S does not properly implement RSA authentication, which allows remote attackers to obtain login access by leveraging knowledge of a username and the associated public key, aka Bug ID CSCus73013.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6280?
CVE-2015-6280 has a high severity rating due to its potential to allow unauthorized remote access.
How do I fix CVE-2015-6280?
To fix CVE-2015-6280, upgrade to the recommended Cisco IOS versions provided in security advisories.
What systems are affected by CVE-2015-6280?
CVE-2015-6280 affects several versions of Cisco IOS and IOS XE, specifically versions 15.2 through 15.5 and specific IOS XE versions.
What type of vulnerability is CVE-2015-6280?
CVE-2015-6280 is an authentication vulnerability that improperly implements RSA authentication in SSHv2.
Can CVE-2015-6280 be exploited remotely?
Yes, CVE-2015-6280 can be exploited remotely, allowing attackers to gain unauthorized access to affected devices.