Vulnerability record · CVE-2016-6415 · published 19 September 2016
CVE-2016-6415: Cisco IOS IKEv1 memory disclosure via SA negotiation
Cisco · Ios
The IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker to read sensitive information from device memory. Because IKEv1 is commonly exposed on internet-facing VPN gateways, the flaw can leak memory contents that aid further attacks.
Description
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with unauthenticated network reachability, confirmed KEV listing and very high EPSS make this a high-priority exposure despite being information disclosure only.
What it is
The IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker to read sensitive information from device memory. Because IKEv1 is commonly exposed on internet-facing VPN gateways, the flaw can leak memory contents that aid further attacks.
Impact
An unauthenticated remote attacker gains read access to device memory, potentially exposing keys, credentials or configuration data that can be used to escalate or pivot. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network through the IKEv1 service (UDP 500/4500) with no authentication or user interaction required, as reflected by the AV:N/PR:N/UI:N vector. Any device running an affected IOS, IOS XE, IOS XR or PIX release with IKEv1 enabled is exposed.
Exploitation
The vulnerability is listed in CISA KEV (added 2023-05-19) and has a very high EPSS probability (0.873, 99.7th percentile), indicating observed exploitation in the wild. No ransomware campaign use is documented.
What to do
- Apply the Cisco vendor advisory updates for IOS, IOS XE, IOS XR and PIX as the primary fix.
- Where patching is not immediate, disable IKEv1 and migrate to IKEv2, or restrict IKEv1 access to trusted peer addresses.
- Block or filter UDP 500/4500 from untrusted networks at the perimeter.
- Monitor Cisco advisories for updated fixed releases and track the KEV remediation due date.
- Inventory internet-facing devices running affected IOS/IOS XE/IOS XR/PIX versions to scope exposure.
Detection
- Review device logs for anomalous or malformed IKEv1 SA negotiation requests and repeated negotiation failures.
- Monitor network traffic to IKE endpoints for unusual request patterns or scanning of UDP 500/4500.
- Audit exposed VPN gateways for IKEv1 enablement and compare running versions against the Cisco advisory.
- Correlate IDS/IPS signatures for BENIGNCERTAIN-related IKEv1 activity with device logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-6415 to the Known Exploited Vulnerabilities catalog on 19 May 2023 as "Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 9 June 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1 | Vendor Advisory |
| http://www.securityfocus.com/bid/93003 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1036841 | Third Party AdvisoryVDB Entry |
| http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1 | Vendor Advisory |
| http://www.securityfocus.com/bid/93003 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1036841 | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6415 | US Government Resource |
Track CVE-2016-6415 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6415), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.