CVE-2015-4216

Description

The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH root authorized key across different customers installations, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of a private key from another installation, aka Bug IDs CSCuu95988, CSCuu95994, and CSCuu96630.

Risk Information

Base Score
7.2
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.882

Associated Vulnerability

VulnerabilityOS Platform
Multiple Default SSH Keys Vulnerabilities in Cisco Virtual WSA, ESA, and SMA For Cisco IronPort Web Security Appliance SoftwareNCM
Multiple Default SSH Keys Vulnerabilities in Cisco Virtual WSA, ESA, and SMA For Cisco IronPort Email Security Appliance SoftwareNCM
Multiple Default SSH Keys Vulnerabilities in Cisco Virtual WSA, ESA, and SMA For Cisco IronPort Security Management Appliance SoftwareNCM
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-4216)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706023Security Update for Cisco IronPort Web Security Appliance Software 9.1.2-010
PATCH-1706003Security Update for Cisco IronPort Email Security Appliance Software 9.7.2-131
PATCH-1706033Security Update for Cisco IronPort Security Management Appliance Software 11.0.1-152

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234