CVE-2015-6316

medium Cisco
CVSS v3 Base Score
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS Score
0.6%
Exploitation probability in 30 days
Top 31% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Published: November 6, 2015 (3842 days ago)
Last Modified: May 6, 2026
Vendor: Cisco
Source: NVD

Description

The default configuration of sshd_config in Cisco Mobility Services Engine (MSE) through 8.0.120.7 allows logins by the oracle account, which makes it easier for remote attackers to obtain access by entering this account's hardcoded password in an SSH session, aka Bug ID CSCuv40501.

CWE

CWE-255

Affected Products

cisco mobility services engine

References