CVE-2015-6358: Medium severity cisco rv320 vulnerability
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6358?
CVE-2015-6358 has a high severity rating due to its potential for remote exploitation and the ability to conduct man-in-the-middle attacks.
How do I fix CVE-2015-6358?
To fix CVE-2015-6358, update the affected Cisco firmware to a version that does not include hardcoded X.509 certificates and SSH host keys.
Which devices are affected by CVE-2015-6358?
Devices such as Cisco RV320, RV325, RVS4000, WRV210, and WAP4410N firmware are among those affected by CVE-2015-6358.
What attacks can CVE-2015-6358 enable?
CVE-2015-6358 can enable remote attackers to bypass cryptographic protections and perform man-in-the-middle attacks.
Is CVE-2015-6358 still a risk for unpatched devices?
Yes, CVE-2015-6358 remains a significant risk for any unpatched Cisco devices that utilize the impacted firmware versions.