ZeroHour

CVE-2016-6415

KEVmass

IKEv1 Memory Disclosure (BENIGNCERTAIN) in Cisco IOS, IOS XE, and IOS XR

CISA: Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

CVSS 3.1
7.5 high
EPSS
87%p100
Published
()
KEV added
AI analysis

CVE-2016-6415, nicknamed BENIGNCERTAIN, is an information disclosure flaw (CWE-200) in the server-side IKEv1 implementation of Cisco IOS, IOS XE, IOS XR, and Cisco PIX firewalls (Bug IDs CSCvb29204 and CSCvb36055). An unauthenticated remote attacker can trigger it by sending a crafted Security Association (SA) negotiation request to a device's IKEv1 listener, causing the device to leak sensitive information from its memory. The attacker gains access to those leaked memory contents, which may include sensitive secrets such as keys or credentials used by the device. Organizations running affected Cisco IOS 12.2 through 12.4 or 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x or 5.0.x through 5.2.x, or PIX before 7.0 with IKEv1 enabled are affected. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-05-19, confirming in-the-wild exploitation, and EPSS assigns it an 87.3% probability of exploitation within 30 days (100th percentile).

What to do: Upgrade affected IOS, IOS XE, and IOS XR devices to fixed releases per Cisco's advisory for CVE-2016-6415, as required by the CISA KEV listing; as an interim mitigation, disable IKEv1 where unused or restrict ISAKMP (UDP 500) access to trusted peers. Inventory internet-facing Cisco routers, switches, and firewalls for IKEv1-enabled configurations, since only devices with IKEv1 enabled are exploitable.

Affected
Cisco IOS12.2 through 12.4 and 15.0 through 15.6
Cisco IOS XEthrough 3.18S
Cisco IOS XR4.3.x and 5.0.x through 5.2.x
Cisco PIXbefore 7.0
Estimated exposure
massroughly 840,000+ exposed Cisco systems (2016 internet-wide scan estimates) — Contemporaneous public internet scans counted more than 840,000 Cisco systems when the flaw was disclosed, and IKEv1 is commonly enabled on internet-facing VPN gateways and concentrators running IOS, IOS XE, and IOS XR, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

CISA Known Exploited Vulnerability
Affected
Cisco IOS, IOS XR, and IOS XE
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe, ios xr
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news