Vulnerability record · CVE-2016-1287 · published 11 February 2016
CVE-2016-1287: Cisco ASA IKEv1/IKEv2 buffer overflow allows remote code execution
Cisco · Adaptive Security Appliance Software
Cisco ASA Software contains a buffer overflow in its IKEv1 and IKEv2 implementations, reachable via crafted UDP packets. It affects ASA 5500, 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module and ISA 3000 devices running the listed firmware versions. Because it is remotely reachable without authentication and can lead to code execution or device reload, it is a serious perimeter risk.
Description
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 devices, ASA 5500-X devices, ASA Services Module for Cisco Catalyst 6500 and Cisco 7600 devices, ASA 1000V devices, Adaptive Security Virtual Appliance (aka ASAv), Firepower 9300 ASA Security Module, and ISA 3000 devices allows remote attackers to execute arbitrary code or cause a denial of service (device reload) via crafted UDP packets, aka Bug IDs CSCux29978 and CSCux42019.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code available, and very high EPSS probability make this an urgent perimeter fix.
What it is
Cisco ASA Software contains a buffer overflow in its IKEv1 and IKEv2 implementations, reachable via crafted UDP packets. It affects ASA 5500, 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module and ISA 3000 devices running the listed firmware versions. Because it is remotely reachable without authentication and can lead to code execution or device reload, it is a serious perimeter risk.
Impact
A remote attacker can execute arbitrary code on the affected appliance or force a denial of service via device reload. Code execution on an edge firewall or VPN concentrator can expose or bypass protected networks.
Attack surface
Reached over the network through IKEv1/IKEv2 UDP traffic; the CVSS vector shows no privileges and no user interaction required. Any host able to send IKE packets to the device can attempt it.
Exploitation
Public exploit code and technical descriptions exist (Exploit and Technical Description reference tags), and EPSS is 0.74795 (99.5th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.
What to do
- Upgrade ASA Software to a fixed release (8.4(7.30), 8.7(1.18), 9.0(4.38), 9.1(7), 9.2(4.5), 9.3(3.7), 9.4(2.4), 9.5(2.2) or later) as applicable to your train.
- If immediate patching is not possible, restrict IKE UDP (500/4500) access to trusted peers only and disable IKE where it is not needed.
- Monitor Cisco advisory cisco-sa-20160210-asa-ike and vendor guidance for interim workarounds.
- Review exposure of ASA management and VPN interfaces to untrusted networks and segment them where feasible.
Detection
- Alert on unexpected ASA device reloads or crashes correlated with inbound IKE traffic.
- Monitor for anomalous or malformed IKEv1/IKEv2 packets to UDP 500/4500 from untrusted sources.
- Watch for signs of post-exploitation activity on ASA devices, such as unexpected configuration changes or new accounts.
- Use IDS/IPS signatures for the known public exploit against Cisco ASA IKE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-1287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-1287), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.