CVE-2016-6415
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 9 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 87.31% probability · 100th percentile
- CISA KEV
- Listed 19 May 2023 · due 9 June 2023
- Weakness
- CWE-200
- Affected
- cisco/ios · cisco/ios xe · cisco/ios xr
- Source
- psirt@cisco.com
CISA notes
Apply updates per vendor instructions. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1; https://nvd.nist.gov/vuln/detail/CVE-2016-6415
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1Vendor Advisory
- http://www.securityfocus.com/bid/93003Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036841Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1Vendor Advisory
- http://www.securityfocus.com/bid/93003Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036841Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6415US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.