CVE-2015-6316 describes a critical vulnerability in Cisco Mobility Services Engine (MSE) versions through 8.0.120.7, where the default sshd_config allows logins via a hardcoded password for the 'oracle' account. This vulnerability carries a CVSS score of 6.5, indicating a medium severity risk, as it permits remote attackers to gain unauthorized access with low attack complexity and authentication. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community. Despite its age, the presence of a hardcoded password represents a significant security oversight.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.1_baseCPE matchmatch criteria | cpe:2.3:a:cisco:mobility_services_engine:5.1_base:*:*:*:*:*:*:* | ||
5.2_baseCPE matchmatch criteria | cpe:2.3:a:cisco:mobility_services_engine:5.2_base:*:*:*:*:*:*:* | ||
6.0_baseCPE matchmatch criteria | cpe:2.3:a:cisco:mobility_services_engine:6.0_base:*:*:*:*:*:*:* | ||
7.0_baseCPE matchmatch criteria | cpe:2.3:a:cisco:mobility_services_engine:7.0_base:*:*:*:*:*:*:* | ||
7.4.100.0CPE matchmatch criteria | cpe:2.3:a:cisco:mobility_services_engine:7.4.100.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.