CVE-2015-6280 describes an authentication bypass vulnerability in the SSHv2 functionality of Cisco IOS and IOS XE. This flaw allows remote attackers to gain unauthorized login access by exploiting improper RSA authentication, requiring only knowledge of a valid username and its associated public key. With a CVSS score of 9.3, this vulnerability is critical, enabling complete compromise of confidentiality, integrity, and availability with medium attack complexity and no authentication required. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it did receive limited media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(1\)syCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(1\)sy:*:*:*:*:*:*:* | ||
15.2\(1\)sy0aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(1\)sy0a:*:*:*:*:*:*:* | ||
15.2\(2\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2\)e:*:*:*:*:*:*:* | ||
15.2\(2\)e1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2\)e1:*:*:*:*:*:*:* | ||
15.2\(2\)e2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2\)e2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.