CVE-2016-6415
published 2016-09-19CVE-2016-6415: The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX…
PriorityP185high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-09
Exploited in the wild
EPSS
87.31%
99.7th percentile
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | 12.2 – 12.4 | — |
| cisco | ios | 15.0 – 15.6 | — |
| cisco | ios_xe | <= 3.18s | — |
| cisco | ios_xr | 4.3.0 – 4.3.4 | — |
| cisco | ios_xr | >= 5.0.0 < 5.3.0 | 5.3.0 |
| cisco | products | — | — |
Detection & IOCsextracted from sources · hover to see the quote
port500/udp
snort
alert udp $EXTERNAL_NET any -> $HOME_NET 500 (msg:"ET EXPLOIT Possible Cisco IKEv1 Information Disclosure Vulnerability CVE-2016-6415"; dsize:>828; content:"|00 00 00 00 00 00 00 00 01 10|"; offset:8; depth:10; content:"|80 02 00|"; distance:30; byte_test:1,,0,0,relative; content:"|80 04 00 01 00 06|"; distance:1; within:6; fast_pattern; byte_test:2,>,768,0,relative; reference:cve,2016-6415; classtype:attempted-user; sid:2023311; rev:1; metadata:affected_product Cisco_PIX, attack_target Networking_Equipment, created_at 2016_09_29, cve CVE_2016_6415, deployment Datacenter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2019_07_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1082, mitre_technique_name System_Information_Discovery;)
bytes
|00 00 00 00 00 00 00 00 01 10| at offset 8, depth 10 in UDP payload
bytes
|80 04 00 01 00 06| within IKEv1 SA negotiation payload
bytes
|80 02 00| within IKEv1 SA negotiation payload
- →Exploit traffic targets UDP port 500 (ISAKMP/IKE) with crafted IKEv1 Security Association negotiation packets. Minimum packet size threshold is >828 bytes.
- →The exploit sends a crafted IKEv1 packet to devices configured to accept IKEv1 security negotiation requests; look for anomalously large IKEv1 SA negotiation packets from external sources. ↗
- →Successful exploitation results in memory contents being returned in the IKEv1 response; monitor for unexpectedly large or malformed IKEv1 responses from Cisco IOS/IOS XE/IOS XR/PIX devices. ↗
- →The Metasploit auxiliary module cisco_ike_benigncertain can be used to validate exposure; presence of this module in scan logs against 500/udp indicates active exploitation attempts. ↗
- ·Only devices configured to accept IKEv1 security negotiation requests are exploitable; IKEv2-only configurations are not affected. ↗
- ·There are no workarounds that address this vulnerability; only vendor software updates remediate it. ↗
- ·Affected platforms span Cisco IOS 12.2–12.4 and 15.0–15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x–5.2.x, and PIX before 7.0; scope is broad across Cisco network infrastructure. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
cisa·2023-05-19·CVSS 7.5
CVE-2016-6415 [HIGH] CWE-200 Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
Vulnerability: Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
Affected: Cisco IOS, IOS XR, and IOS XE
Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.
Required Action: Apply updates per vendor instructions.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1; https://nvd.nist.gov/vuln/detail/CVE-2016-6415
Remed
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Cisco
IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products
vendor_cisco·2016-09-16·CVSS 7.8
CVE-2016-6415 [HIGH] IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products
IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products
A vulnerability in Internet Key Exchange version 1 (IKEv1) packet processing code in Cisco IOS, Cisco IOS XE, and Cisco IOS XR Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information.The vulnerability is due to insufficient condition checks in the part of the code that handles IKEv1 security negotiation requests. An attacker could exploit this vulnerability by sending a crafted IKEv1 packet to an affected device configured to accept IKEv1 security negotiation requests. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information.Cisco will release soft
Cisco
IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products
vendor_cisco
CVE-2016-6415 IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products
CVE-2016-6415: IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products
A vulnerability in Internet Key Exchange version 1 (IKEv1) packet processing code in Cisco IOS, Cisco IOS XE, and Cisco IOS XR Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the part of the code that handles IKEv1 security negotiation requests. An attacker could exploit this vulnerability by sending a crafted IKEv1 packet to an affected device configured to accept IKEv1 security negotiation requests. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Cisco wi
GHSA
GHSA-ccm6-q86p-2hwx: The server IKEv1 implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2016-6415 [HIGH] CWE-200 GHSA-ccm6-q86p-2hwx: The server IKEv1 implementation in Cisco IOS 12
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.
VulnCheck
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
vulncheck·2016·CVSS 7.5
CVE-2016-6415 [HIGH] CWE-200 Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/ncas/alerts/TA16-250A; https://cisa.gov/news-events/alerts/2015/08/01/recent-email-phishing-campaigns-mitigation-and-response; http
Suricata
ET EXPLOIT Possible Cisco IKEv1 Information Disclosure Vulnerability CVE-2016-6415
suricata·2016-09-29·CVSS 7.5
CVE-2016-6415 [HIGH] ET EXPLOIT Possible Cisco IKEv1 Information Disclosure Vulnerability CVE-2016-6415
ET EXPLOIT Possible Cisco IKEv1 Information Disclosure Vulnerability CVE-2016-6415
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 500 (msg:"ET EXPLOIT Possible Cisco IKEv1 Information Disclosure Vulnerability CVE-2016-6415"; dsize:>828; content:"|00 00 00 00 00 00 00 00 01 10|"; offset:8; depth:10; content:"|80 02 00|"; distance:30; byte_test:1,,0,0,relative; content:"|80 04 00 01 00 06|"; distance:1; within:6; fast_pattern; byte_test:2,>,768,0,relative; reference:cve,2016-6415; classtype:attempted-user; sid:2023311; rev:1; metadata:affected_product Cisco_PIX, attack_target Networking_Equipment, created_at 2016_09_29, cve CVE_2016_6415, deployment Datacenter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2019_07_26, mitre_tactic_id TA0007, m
Exploit-DB
Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory
exploitdb·2017-03-17
CVE-2016-6415 Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory
Cisco IOS 12.2 5\xc7\x07)\xdf\xed\xef\x00\x00\x00\x00\x00\x00\x00\x00\x01\x10\x02'
payload += '\x00\x00\x00\x00\x00\x00\x00\t\xe0\x00\x00\t\xc4\x00\x00\x00\x01'
payload += '\x00\x00\x00\x01\x00\x00\t\xb8\x01\x01\x04\x01.\xbf\x19'
payload += '\x99$*\xde\xa2;\xe2\n\xe4\xb8\xeb3B\x06\xb5\xab\xc3A\xe62N'
payload += '\xb4B\xabY\x1a\x08\xa5mb\x91\xda\xd73\x8e\xbd\x07\xea\xf3\xbf'
payload += '\x1c\xce\x89\n{UX\xd5W\x91M\x17\xe7\xa4\xdf~\x9dH\x83\xab\x92'
payload += '\xfciJ\x8e\xe3k\x8a\xd3\xd1*\x81.\x99\x03S;8\xb4SE\xd2.S/\xc5'
payload += '\x87\xa1\x11$\xfd\xa6\xf0\x1e\xfe\x9f\'B\x87\x00Z\x88b"\x1ceq'
payload += '\xdb\t\x81\xb7\xef\xf6\xb3n\xc6 \x83\xa3\xea\x0b;\xba\xe1\x81'
payload += '\x07\x91\xac\x11\x87\x9a\xc08\xd2E\xc2PfA\xadW6\xd3\x12\xebeI'
payload += '\xff\xef\xf0\x834 \x90\xa0\xb1\xf0A\
Metasploit
Cisco IKE Information Disclosure
metasploit
Cisco IKE Information Disclosure
Cisco IKE Information Disclosure
A vulnerability in Internet Key Exchange version 1 (IKEv1) packet processing code in Cisco IOS, Cisco IOS XE, and Cisco IOS XR Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the part of the code that handles IKEv1 security negotiation requests. An attacker could exploit this vulnerability by sending a crafted IKEv1 packet to an affected device configured to accept IKEv1 security negotiation requests. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1http://www.securityfocus.com/bid/93003http://www.securitytracker.com/id/1036841http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1http://www.securityfocus.com/bid/93003http://www.securitytracker.com/id/1036841https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6415
2016-09-19
Published
2023-05-19
Added to CISA KEV
Exploited in the wild