CVE-2015-6358: Cisco PVC2300 Firmware
Medium severity, CVSS 5.9. EPSS: 1.3% chance of exploitation in the next 30 days.
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
Affected products
- Cisco PVC2300 Firmware: up to and including 1.1.2.6
- Cisco RTP300 Firmware: up to and including 3.1.24
- Cisco RV120W Firmware: up to and including 1.0.5.9
- Cisco RV180 Firmware: up to and including 1.0.5.4
- Cisco RV180W Firmware: up to and including 1.0.5.4
- Cisco RV220W Firmware: up to and including 1.0.4.17
- Cisco RV315W Firmware: up to and including 1.01.03
- Cisco RV320 Firmware: up to and including 1.3.1.10
- Cisco RV325 Firmware: up to and including 1.3.1.10
- Cisco RVS4000 Firmware: up to and including 2.0.3.4
- Cisco SPA400 Firmware: up to and including 1.1.2.2
- Cisco SRP520-U Firmware: up to and including 1.2.6
- Cisco SRP520 Firmware: up to and including 1.01.29
- Cisco SRW224P Firmware: up to and including 2.0.2.4
- Cisco WAP2000 Firmware: up to and including 2.0.8.0
- Cisco WAP200 Firmware: up to and including 2.0.6.0
- Cisco WAP4400N Firmware: up to and including -
- Cisco WAP4410N Firmware: up to and including 2.0.7.8
- Cisco WET200 Firmware: up to and including 2.0.8.0
- Cisco WRP500 Firmware: up to and including 1.0.1.002
- Cisco WRV200 Firmware: version 1.0.39 only
- Cisco WRV210 Firmware: up to and including 2.0.1.5
- Cisco WRVS4400N Firmware: up to and including 2.0.2.2
- Cisco WVC2300 Firmware: up to and including 1.1.2.6
Published 2017-10-12. Last modified 2026-06-17.