CVE-2015-4216 describes a critical vulnerability in Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices. The remote-support feature in these appliances utilized a single, default SSH root authorized key across all customer installations. This design flaw allows remote attackers to bypass authentication by reusing a private key obtained from any other affected installation. The vulnerability has a CVSS score of 5.0, indicating a medium severity. Its attack vector is network-based with low attack complexity, requiring no authentication, and potentially leading to partial confidentiality impact. While the EPSS score is low, suggesting a minimal likelihood of exploitation, the FAUCET Risk Score is 17/100. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community attention, with mentions on Reddit and coverage in SecurityWeek, highlighting the risk posed by default SSH keys.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.4.0.0150CPE matchmatch criteria | cpe:2.3:a:cisco:content_security_management_virtual_appliance:8.4.0.0150:*:*:*:*:*:*:* | ||
9.0.0.087CPE matchmatch criteria | cpe:2.3:a:cisco:content_security_management_virtual_appliance:9.0.0.087:*:*:*:*:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_virtual_appliance:8.0.0:*:*:*:*:*:*:* | ||
8.5.6CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_virtual_appliance:8.5.6:*:*:*:*:*:*:* | ||
8.5.7CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_virtual_appliance:8.5.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.