CVE-2016-6415
Summary
| CVE | CVE-2016-6415 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-09-19 01:59:00 UTC |
| Updated | 2020-06-03 15:33:00 UTC |
| Description | The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN. |
Risk And Classification
EPSS: 0.929990000 probability, percentile 0.997800000 (date 2026-04-01)
CISA KEV: Listed on 2023-05-19; due 2023-06-09; ransomware use Unknown
Problem Types: CWE-200
CISA Known Exploited Vulnerability
| Vendor | Cisco |
|---|---|
| Product | IOS, IOS XR, and IOS XE |
| Name | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1; https://nvd.nist.gov/vuln/detail/CVE-2016-6415 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Ios | All | All | All | All |
| Operating System | Cisco | Ios | All | All | All | All |
| Operating System | Cisco | Ios Xe | All | All | All | All |
| Operating System | Cisco | Ios Xr | All | All | All | All |
| Operating System | Cisco | Ios Xr | All | All | All | All |
| Operating System | Cisco | Ios Xr | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS, IOS XE, and IOS XR IKEv1 Processing Flaw Lets Remote Users Obtain Memory Contents on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products | CISCO | tools.cisco.com | Vendor Advisory |
| Multiple Cisco Products CVE-2016-6415 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590349 Rockwell Automation Stratix 5900 Multiple Vulnerabilities (ICSA-17-094-04)