Executive brief
Cisco IOS, IOS XE, and IOS XR contain an information disclosure vulnerability in the IKEv1 implementation due to insufficient condition checks during Security Association (SA) negotiation. A remote, unauthenticated attacker can exploit this by sending a crafted IKEv1 request to retrieve sensitive memory contents from the affected device.
Affected products
- Cisco IOS 12.2 through 12.4, 15.0 through 15.6
- Cisco IOS XE through 3.18S
- Cisco IOS XR 4.3.x, 5.0.x through 5.2.x
- Cisco PIX before 7.0
Timeline
- 2016-09-16: disclosed: Initial Cisco Security Advisory published
- 2023-05-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog