CVE-2015-6420

Description

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
21.2

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-7501,CVE-2015-6420 are fixed in Apache-commons-collections 3.2.2Windows
Vulnerabilities CVE-2015-7501,CVE-2015-6420 are fixed in Apache-commons-collections4 4.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 11.0.1Windows
Vulnerabilities CVE-2015-6420 are affected in Sourceforge - collections-generic 4.0.1Windows
Vulnerabilities CVE-2015-6420 are affected in Apache - org.apache.servicemix.bundles.collections-generic 4.01Windows
Vulnerabilities CVE-2015-6420 are affected in Apache - org.apache.servicemix.bundles.commons-collections 3.2.1Windows
Vulnerabilities CVE-2015-7501,CVE-2015-6420 are fixed in Apache-commons-collections for Linux 3.2.2Linux
Vulnerabilities CVE-2015-7501,CVE-2015-6420 are fixed in Apache-commons-collections4 for Linux 4.1Linux
Vulnerabilities CVE-2015-6420 are affected in Sourceforge - collections-generic for Linux 4.0.1Linux
Vulnerabilities CVE-2015-6420 are affected in Apache - org.apache.servicemix.bundles.collections-generic for Linux 4.01Linux
Vulnerabilities CVE-2015-6420 are affected in Apache - org.apache.servicemix.bundles.commons-collections for Linux 3.2.1Linux
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Emergency ResponderNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco MediaSenseNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Mobility Services EngineNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Prime HomeNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Prime InfrastructureNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Prime OpticalNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Prime Performance ManagerNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Prime ProvisioningNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Prime Service CatalogNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Security ManagerNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco UCS DirectorNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified Contact Center EnterpriseNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified E-Mail Interaction ManagerNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified Intelligence CenterNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified SIP ProxyNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unity ConnectionNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unity ExpressNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Applications for Cisco Unified Application EnvironmentNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco IronPort Encryption Appliance SoftwareNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Broadband Access Center for Telco and WirelessNCM
Vulnerability in Java Deserialization Affecting Cisco Products For CiscoWorks Common Services SoftwareNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Access RegistrarNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Prime CollaborationNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Virtual Network Management CenterNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Collaboration Meeting Rooms (CMR)NCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Digital Media ManagerNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified Communications LicensingNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Videoscape Distribution Suite for Internet StreamingNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco ASA Next-Generation Firewall ServicesNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Secure Access Control Server Solution EngineNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco ConductorNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified Attendant ConsolesNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified Communications Manager (CallManager)NCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Hosted Collaboration Solution (HCS)NCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco NAC Appliance (Clean Access)NCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified Customer Voice PortalNCM
Vulnerability in Java Deserialization Affecting Cisco Products For Cisco Unified MeetingPlaceNCM
Deserialization of Untrusted Data Vulnerability (CVE-2015-6420)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706049Security Update for Cisco Emergency Responder 12.0(0.98000.50)
PATCH-1705879Security Update for Cisco MediaSense 11.5(1.10000.6)
PATCH-1705808Security Update for Cisco Mobility Services Engine 8.0(130.12)
PATCH-1701797Security Update for Cisco Prime Home 6.5(1)
PATCH-1705595Security Update for Cisco Prime Infrastructure 2.2(2)
PATCH-1706040Security Update for Cisco Prime Optical 10.6(1)
PATCH-1706037Security Update for Cisco Prime Performance Manager 1.7(0.1703)
PATCH-1705717Security Update for Cisco Prime Provisioning 6.8
PATCH-1706010Security Update for Cisco Prime Service Catalog 11.1_VA_OS_Patch
PATCH-1705795Security Update for Cisco Security Manager 4.12(0.64)
PATCH-1705947Security Update for Cisco UCS Director 6.0(1.0)
PATCH-1705943Security Update for Cisco Unified Contact Center Enterprise 11.6(1)SR0(0)
PATCH-1705669Security Update for Cisco Unified E-Mail Interaction Manager 11.0(1)
PATCH-1705886Security Update for Cisco Unified Intelligence Center 11.5(0.98000.126)
PATCH-1705497Security Update for Cisco Unified SIP Proxy 8.5(5)
PATCH-1706048Security Update for Cisco Unity Connection 12.0(0.97000.184)
PATCH-1703070Security Update for Cisco Unity Express 6.2.1
PATCH-1705477Security Update for CiscoWorks Common Services Software 4.2(4)
PATCH-1706039Security Update for Cisco Access Registrar 8.0
PATCH-1705997Security Update for Cisco Prime Collaboration 11.0(0.815)
PATCH-1705797Security Update for Cisco Digital Media Manager 5.6.3
PATCH-1706042Security Update for Cisco Unified Communications Licensing 11.5(1.12001.2)
PATCH-1705993Security Update for Cisco Videoscape Distribution Suite for Internet Streaming 3.11(6.2)
PATCH-1705897Security Update for Cisco ASA Next-Generation Firewall Services 100.6(0.0.181)
PATCH-1705698Security Update for Cisco Secure Access Control Server Solution Engine 5.8(0.32.2)
PATCH-1705867Security Update for Cisco Conductor 3.600
PATCH-1706047Security Update for Cisco Unified Attendant Consoles 11.0(2)
PATCH-1706016Security Update for Cisco Unified Communications Manager (CallManager) CUP.11.5(1.12900.25)
PATCH-1706050Security Update for Cisco Hosted Collaboration Solution (HCS) 11.5(1.93540.24)
PATCH-1705725Security Update for Cisco NAC Appliance (Clean Access) 4.9(5)
PATCH-1705727Security Update for Cisco Unified Customer Voice Portal 11.0(1)SR0(24)
PATCH-1705973Security Update for Cisco Unified MeetingPlace 8.6(2.45)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234