← Back to CVE List
Vulnerability Intelligence Report
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

CVE-2016-6415

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:87.69%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-200 ↗CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected Products & Versions

Vendor Product Affected Versions
cisco ios all
cisco ios_xe all
cisco ios_xr all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
87.687%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCisco Systems, Inc. · Hosted Service · USA
Reserved2016-07-26T00:00:00
Published2016-09-19T01:00:00
Patch Date2016-09-16
Last Updated2026-01-12T21:16:07

LINK COPIED TO CLIPBOARD