← Vulnerability feed

Vulnerability record · CVE-2016-1287 · published 11 February 2016

CVE-2016-1287: Cisco ASA IKEv1/IKEv2 buffer overflow allows remote code execution

Cisco · Adaptive Security Appliance Software

Cisco ASA Software contains a buffer overflow in its IKEv1 and IKEv2 implementations, reachable via crafted UDP packets. It affects ASA 5500, 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module and ISA 3000 devices running the listed firmware versions. Because it is remotely reachable without authentication and can lead to code execution or device reload, it is a serious perimeter risk.

9.8 CVSS 3.0 Critical EPSS 74% · top 0.5% CWE-119 · Memory buffer overflow
9.8CVSS 3.0 base score, v2 10.0
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 devices, ASA 5500-X devices, ASA Services Module for Cisco Catalyst 6500 and Cisco 7600 devices, ASA 1000V devices, Adaptive Security Virtual Appliance (aka ASAv), Firepower 9300 ASA Security Module, and ISA 3000 devices allows remote attackers to execute arbitrary code or cause a denial of service (device reload) via crafted UDP packets, aka Bug IDs CSCux29978 and CSCux42019.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code available, and very high EPSS probability make this an urgent perimeter fix.

What it is

Cisco ASA Software contains a buffer overflow in its IKEv1 and IKEv2 implementations, reachable via crafted UDP packets. It affects ASA 5500, 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module and ISA 3000 devices running the listed firmware versions. Because it is remotely reachable without authentication and can lead to code execution or device reload, it is a serious perimeter risk.

Impact

A remote attacker can execute arbitrary code on the affected appliance or force a denial of service via device reload. Code execution on an edge firewall or VPN concentrator can expose or bypass protected networks.

Attack surface

Reached over the network through IKEv1/IKEv2 UDP traffic; the CVSS vector shows no privileges and no user interaction required. Any host able to send IKE packets to the device can attempt it.

Exploitation

Public exploit code and technical descriptions exist (Exploit and Technical Description reference tags), and EPSS is 0.74795 (99.5th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade ASA Software to a fixed release (8.4(7.30), 8.7(1.18), 9.0(4.38), 9.1(7), 9.2(4.5), 9.3(3.7), 9.4(2.4), 9.5(2.2) or later) as applicable to your train.
  • If immediate patching is not possible, restrict IKE UDP (500/4500) access to trusted peers only and disable IKE where it is not needed.
  • Monitor Cisco advisory cisco-sa-20160210-asa-ike and vendor guidance for interim workarounds.
  • Review exposure of ASA management and VPN interfaces to untrusted networks and segment them where feasible.

Detection

  • Alert on unexpected ASA device reloads or crashes correlated with inbound IKE traffic.
  • Monitor for anomalous or malformed IKEv1/IKEv2 packets to UDP 500/4500 from untrusted sources.
  • Watch for signs of post-exploitation activity on ASA devices, such as unexpected configuration changes or new accounts.
  • Use IDS/IPS signatures for the known public exploit against Cisco ASA IKE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-1287 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed7.5CVE-2020-3452Cisco ASA and FTD web services path traversal file readCisco ASA and FTD web services fail to validate URL input, allowing directory traversal sequences in HTTP requests to read files inside the web servi…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2016-1287), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.