LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-6415: Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 19, 2023
CVSS 7.5 · High⚠ Actively exploited (CISA KEV)
7.5
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 9, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-6415 to its Known Exploited Vulnerabilities catalog on May 19, 2023, with a federal patch deadline of Jun 9, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

CVE-2016-6415 is an information disclosure vulnerability affecting Cisco IOS, IOS XR, and IOS XE. It stems from insufficient condition checks when handling Internet Key Exchange version 1 (IKEv1) security negotiation requests, allowing an attacker to retrieve memory contents from the device. This matters because exposed memory can contain sensitive operational data, credentials, or configuration details that aid further compromise of network infrastructure.

Defenders should treat this as a network-device risk that can leak internal state without authentication in some cases. Confirm exact impact and affected releases against the vendor advisory before acting.

How it works

The weakness is classified as CWE-200 (Information Exposure). Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the code that processes IKEv1 security negotiation requests. An unauthenticated remote attacker can send specially crafted IKEv1 packets that cause the device to return portions of its memory contents in the response. Successful exploitation yields information disclosure rather than direct code execution or denial of service. Specific packet formats or memory regions that can be read are not detailed in the public summary; treat any such claims as unconfirmed until verified against the vendor advisory.

Am I affected? How to find it in your systems

Cisco IOS, IOS XR, and IOS XE typically run on enterprise routers, switches, and other network infrastructure devices that terminate or process IPsec/VPN traffic. Inventory all Cisco devices in your environment that support IKEv1. Check running software images and configuration for IKEv1 enablement (for example, crypto isakmp or related IKE policies). Because exact vulnerable versions are not listed here, compare your installed releases against the official Cisco advisory for CVE-2016-6415.

If IKEv1 is not in use, the attack surface is reduced but still confirm the software version against the advisory.

How to remediate

Apply the vendor-supplied software updates for Cisco IOS, IOS XR, and IOS XE as directed in the official advisory. CISA guidance is simply to apply updates per vendor instructions. After patching, verify that the fixed image is running and that IKEv1 behavior matches expected post-update operation.

Additional hardening for this class of issue includes:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These steps lower risk but do not eliminate the underlying code flaw; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited information-disclosure vulnerabilities on network devices can lead to broader breaches when memory contents reveal credentials or topology. Ransomware use of this specific CVE is not documented. If you suspect exposure, review device logs for signs of exploitation, rotate any credentials that may have been present in memory, and consider running a free exposure scan of organizational email addresses against known breach data sets to check for secondary credential compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS, IOS XR, and IOS XE
WeaknessCWE-200
CVSS base score7.5 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
PublishedSep 19, 2016
Added to CISA KEVMay 19, 2023
Federal patch deadlineJun 9, 2023
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities