Junglewise Threat Intelligence

CVE-2016-6415: Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

CVE-2016-6415 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2023-05-19

Technologies: Cisco IOS, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco.

Executive brief

Cisco IOS, IOS XE, and IOS XR contain an information disclosure vulnerability in the IKEv1 implementation due to insufficient condition checks during Security Association (SA) negotiation. A remote, unauthenticated attacker can exploit this by sending a crafted IKEv1 request to retrieve sensitive memory contents from the affected device.

Affected products

  • Cisco IOS 12.2 through 12.4, 15.0 through 15.6
  • Cisco IOS XE through 3.18S
  • Cisco IOS XR 4.3.x, 5.0.x through 5.2.x
  • Cisco PIX before 7.0

Timeline

  • 2016-09-16: disclosed: Initial Cisco Security Advisory published
  • 2023-05-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats