← Vulnerability feed

Vulnerability record · CVE-2016-6415 · published 19 September 2016

CVE-2016-6415: Cisco IOS IKEv1 memory disclosure via SA negotiation

Cisco · Ios

The IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker to read sensitive information from device memory. Because IKEv1 is commonly exposed on internet-facing VPN gateways, the flaw can leak memory contents that aid further attacks.

7.5 CVSS 3.1 High CISA KEV since 19 May 2023 EPSS 88% · top 0.2% CWE-200 · Information exposure
7.5CVSS 3.1 base score, v2 5.0
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.5 with unauthenticated network reachability, confirmed KEV listing and very high EPSS make this a high-priority exposure despite being information disclosure only.

What it is

The IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker to read sensitive information from device memory. Because IKEv1 is commonly exposed on internet-facing VPN gateways, the flaw can leak memory contents that aid further attacks.

Impact

An unauthenticated remote attacker gains read access to device memory, potentially exposing keys, credentials or configuration data that can be used to escalate or pivot. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network through the IKEv1 service (UDP 500/4500) with no authentication or user interaction required, as reflected by the AV:N/PR:N/UI:N vector. Any device running an affected IOS, IOS XE, IOS XR or PIX release with IKEv1 enabled is exposed.

Exploitation

The vulnerability is listed in CISA KEV (added 2023-05-19) and has a very high EPSS probability (0.873, 99.7th percentile), indicating observed exploitation in the wild. No ransomware campaign use is documented.

What to do

  • Apply the Cisco vendor advisory updates for IOS, IOS XE, IOS XR and PIX as the primary fix.
  • Where patching is not immediate, disable IKEv1 and migrate to IKEv2, or restrict IKEv1 access to trusted peer addresses.
  • Block or filter UDP 500/4500 from untrusted networks at the perimeter.
  • Monitor Cisco advisories for updated fixed releases and track the KEV remediation due date.
  • Inventory internet-facing devices running affected IOS/IOS XE/IOS XR/PIX versions to scope exposure.

Detection

  • Review device logs for anomalous or malformed IKEv1 SA negotiation requests and repeated negotiation failures.
  • Monitor network traffic to IKE endpoints for unusual request patterns or scanning of UDP 500/4500.
  • Audit exposed VPN gateways for IKEv1 enablement and compare running versions against the Cisco advisory.
  • Correlate IDS/IPS signatures for BENIGNCERTAIN-related IKEv1 activity with device logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-6415 to the Known Exploited Vulnerabilities catalog on 19 May 2023 as "Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 9 June 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-6415 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2020-3118Cisco IOS XR CDP packet parsing flaw allows adjacent code executionCisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overfl…KEVEPSS 12%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed

Source: NIST National Vulnerability Database (record CVE-2016-6415), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.