CVE-2015-6420

Executive Summary

CVE-2015-6420 exposes a remote code execution vulnerability in multiple Cisco products via crafted serialized Java objects that exploit the Apache Commons Collections library. Attackers can execute arbitrary commands on affected systems, potentially compromising network infrastructure, voice, video, and collaboration services. The flaw is not listed in CISA KEV, but remains a critical risk for organizations running vulnerable Cisco software.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2015-12-15T05:59:07.823 - Last Modified: 2026-10-07T18:17:07.410

Original Description: Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

"Never doubt that a small group of thoughtful, committed people can change the world. Indeed. It is the only thing that ever has."

— Margaret Mead
Source: NVD