CVE-2016-6415
KEVmassIKEv1 Memory Disclosure (BENIGNCERTAIN) in Cisco IOS, IOS XE, and IOS XR
CISA: Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
CVE-2016-6415, nicknamed BENIGNCERTAIN, is an information disclosure flaw (CWE-200) in the server-side IKEv1 implementation of Cisco IOS, IOS XE, IOS XR, and Cisco PIX firewalls (Bug IDs CSCvb29204 and CSCvb36055). An unauthenticated remote attacker can trigger it by sending a crafted Security Association (SA) negotiation request to a device's IKEv1 listener, causing the device to leak sensitive information from its memory. The attacker gains access to those leaked memory contents, which may include sensitive secrets such as keys or credentials used by the device. Organizations running affected Cisco IOS 12.2 through 12.4 or 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x or 5.0.x through 5.2.x, or PIX before 7.0 with IKEv1 enabled are affected. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-05-19, confirming in-the-wild exploitation, and EPSS assigns it an 87.3% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade affected IOS, IOS XE, and IOS XR devices to fixed releases per Cisco's advisory for CVE-2016-6415, as required by the CISA KEV listing; as an interim mitigation, disable IKEv1 where unused or restrict ISAKMP (UDP 500) access to trusted peers. Inventory internet-facing Cisco routers, switches, and firewalls for IKEv1-enabled configurations, since only devices with IKEv1 enabled are exploitable.
| Cisco IOS | 12.2 through 12.4 and 15.0 through 15.6 |
| Cisco IOS XE | through 3.18S |
| Cisco IOS XR | 4.3.x and 5.0.x through 5.2.x |
| Cisco PIX | before 7.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.
- Affected
- Cisco IOS, IOS XR, and IOS XE
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe, ios xr
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N