CVE advisoryCRITICAL
CVE-2015-6420
Cisco Products Command Execution via Java Deserialization Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in the Apache Commons Collections library allows remote attackers to execute arbitrary commands by sending a crafted serialized Java object. This could impact Cisco products and other applications using the library, potentially leading to system compromise. You should care because this critical library