CVE Database
/

CVE-2015-6358

Back to search

CVE-2015-6358

Published: Oct 12, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#566724
third-party-advisory
x_refsource_CERT-VN
1034258
vdb-entry
x_refsource_SECTRACK
78047
vdb-entry
x_refsource_BID
1034255
vdb-entry
x_refsource_SECTRACK
1034257
vdb-entry
x_refsource_SECTRACK
1034256
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now