Cisco-SA-20150616-CVE-2015-4190
Cisco Cloud Portal Appliance Pregenerated Default Host Keys Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
A vulnerability in Cisco Cloud Portal Appliance could aid an unauthenticated, remote attacker in performing a man-in-the-middle attack. The vulnerability is due to a design error in the affected software. An unauthenticated, remote attacker could exploit this vulnerability to perform a man-in-the-middle attack against a user logging in to a targeted device. A successful exploit could be used to conduct further attacks. Cisco has confirmed the vulnerability and released software updates. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
| Product | CVE |
|---|---|
| Cisco Prime Service Catalog | CVE-2015-4190 |