CVE-2015-6418

The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake key-exchange data, aka Bug ID CSCus15224.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
VendorProductVersion
ciscosa520
2.2.07
ciscosa520w
2.2.07
ciscosa540
2.2.07
ciscorv016_multi-wan_vpn_firmware
4.0.0.7
ciscorv016_multi-wan_vpn_firmware
4.0.2.8
ciscorv016_multi-wan_vpn_firmware
4.0.5.0
ciscorv042_dual_wan_vpn_router_firmware
4.0.2.8
ciscorv042g_dual_gigabit_wan_vpn_firmware
4.0.0.7
ciscorv042g_dual_gigabit_wan_vpn_firmware
4.2.2.7
ciscorv042g_dual_gigabit_wan_vpn_firmware
4.2.2.8
ciscorv082_dual_wan_vpn_router_firmware
4.0.0.7
ciscorv082_dual_wan_vpn_router_firmware
4.0.2.8
𝑥
= Vulnerable software versions