Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-6420

42
FAUCET Score

CVE-2015-6420 describes a critical deserialization vulnerability affecting numerous Cisco products across various categories, including Collaboration, Endpoint Clients, Security Devices, and Routing/Switching. This flaw allows remote attackers to execute arbitrary commands by sending a specially crafted serialized Java object, leveraging a weakness in the Apache Commons Collections library. With a CVSS score of 9.8 (Critical), the vulnerability requires no user interaction or authentication and can lead to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, publicly available exploit code in common frameworks, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0, < 3.2.2CPE matchmatch criteria
cpe:2.3:a:apache:commons_collections:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:apache:commons_collections:4.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
18.07%
Probability of exploitation in next 30 days
EPSS Percentile
96.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1807 is in the 93rd percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

mavenpatch availablevia ghsa
Product: org.apache.commons:commons-collections4Fixed in: 4.1
mavenpatch availablevia ghsa
Product: commons-collections:commons-collectionsFixed in: 3.2.2
bindvendor investigatingvia llm_extracted
kerasvendor investigatingvia llm_extracted
lexmarkvendor investigatingvia llm_extracted
libreofficevendor investigatingvia llm_extracted
mitelvendor investigatingvia llm_extracted
postgresqlvendor investigatingvia llm_extracted

Vendor Advisories (8)

mavenGHSA-6hgm-866r-3cjvhigh

Insecure Deserialization in Apache Commons Collection

Jun 15, 2020
kerasllm-keras-0f7230bc12d16a52CRITICAL

[R1] Cisco Security Manager and Prime LMS Java Deserialization Remote Code Execution

Nov 3, 2017
mitelllm-mitel-42b0465523692774CRITICAL

[R1] Cisco Security Manager and Prime LMS Java Deserialization Remote Code Execution

Nov 3, 2017
bindllm-bind-ac45ebcdb71d2d88CRITICAL

Cisco Security Manager and Prime LMS Java Deserialization Remote Code Execution

Nov 3, 2017
postgresqlllm-postgresql-196e575e6b715e9eCRITICAL

[R1] Cisco Unified Customer Voice Portal Java Deserialization Remote Code Execution

Mar 25, 2017
mitelllm-mitel-45fee73cfbf49eedCRITICAL

[R1] Cisco Unified Customer Voice Portal Java Deserialization Remote Code Execution

Mar 25, 2017
libreofficellm-libreoffice-359182e955747951CRITICAL

[R1] Cisco Unified Customer Voice Portal Java Deserialization Remote Code Execution

Mar 25, 2017
lexmarkllm-lexmark-a242374d7d6f9ccfCRITICAL

[R1] Cisco Unified Customer Voice Portal Java Deserialization Remote Code Execution

Mar 25, 2017

References

foxglovesecurity.com / 2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability
ExploitThird Party Advisory
news.apache.org / foundation/entry/apache_commons_statement_to_widespread
Vendor Advisory
kb.cert.org / vuls/id/576313
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
lists.apache.org / thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E
Vendor Advisory
kb.cert.org / vuls/id/581311
Third Party Advisory
tenable.com / security/research/tra-2017-14
Third Party Advisory
tenable.com / security/research/tra-2017-23
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization
Third Party Advisory
oracle.com / technetwork/security-advisory/cpujul2018-4258247.html
Third Party Advisory
securityfocus.com / bid/78872
Third Party AdvisoryVDB Entry