Cisco Virtual WSA, ESA, and SMA Default SSH Host Keys Vulnerability
Customer deployments and images contain a preinstalled set of SSH host keys that allow access to communication secured by those keys. Because all deployments of WSAv or ESAv use the same set of default SSH host keys, accessing any of the private keys on a single deployment could allow an attacker to decrypt communication on WSAv, ESAv, or SMAv.
COMPLETE FAILURE by a security vendor to engineer a secure product.
See http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150625-ironport