Cisco keys Systems announced Thursday that it has released a patch for three default products that ship with encryption keys, raising the possibility that an attacker could obtain the and decrypt data traffic.
The products are the company, E-mail Security Virtual Appliance and Security Management Virtual Appliance. Any versions downloaded before Thursday are vulnerable.
The company said it is "not aware of any public announcement or malicious use of the vulnerabilities to date.".
These three products ship with pre-installed encryption keys for SSH (Secure Shell), which is used to remotely connect to machines. It is considered bad security practice to ship products that all have the same private keys.
If attackers were to find the private keys, they could decrypt the traffic after it was collected during a man-in-the-middle attack. They could also impersonate one of the devices or modify the traffic, Cisco warns.
The fix deletes pre-installed SSH keys and provides instructions on how the customer can fix the issue completely. The company also wrote that the fix is not required for physical hardware devices or for downloads made after Thursday.
The name of the fix is “cisco-sa-20150625-iroport SSH Keys Vulnerability Fix” and it will need to be installed manually.
