cbcvebase.
CVE-2016-6415
published 2016-09-19

CVE-2016-6415: The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX…

PriorityP185high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-09
Exploited in the wild
EPSS
87.31%
99.7th percentile
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscoios12.2 – 12.4
ciscoios15.0 – 15.6
ciscoios_xe<= 3.18s
ciscoios_xr4.3.0 – 4.3.4
ciscoios_xr>= 5.0.0 < 5.3.05.3.0
ciscoproducts

Detection & IOCsextracted from sources · hover to see the quote

port500/udp
snort
alert udp $EXTERNAL_NET any -> $HOME_NET 500 (msg:"ET EXPLOIT Possible Cisco IKEv1 Information Disclosure Vulnerability CVE-2016-6415"; dsize:>828; content:"|00 00 00 00 00 00 00 00 01 10|"; offset:8; depth:10; content:"|80 02 00|"; distance:30; byte_test:1,,0,0,relative; content:"|80 04 00 01 00 06|"; distance:1; within:6; fast_pattern; byte_test:2,>,768,0,relative; reference:cve,2016-6415; classtype:attempted-user; sid:2023311; rev:1; metadata:affected_product Cisco_PIX, attack_target Networking_Equipment, created_at 2016_09_29, cve CVE_2016_6415, deployment Datacenter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2019_07_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1082, mitre_technique_name System_Information_Discovery;)
bytes
|00 00 00 00 00 00 00 00 01 10| at offset 8, depth 10 in UDP payload
bytes
|80 04 00 01 00 06| within IKEv1 SA negotiation payload
bytes
|80 02 00| within IKEv1 SA negotiation payload
  • Exploit traffic targets UDP port 500 (ISAKMP/IKE) with crafted IKEv1 Security Association negotiation packets. Minimum packet size threshold is >828 bytes.
  • The exploit sends a crafted IKEv1 packet to devices configured to accept IKEv1 security negotiation requests; look for anomalously large IKEv1 SA negotiation packets from external sources.
  • Successful exploitation results in memory contents being returned in the IKEv1 response; monitor for unexpectedly large or malformed IKEv1 responses from Cisco IOS/IOS XE/IOS XR/PIX devices.
  • The Metasploit auxiliary module cisco_ike_benigncertain can be used to validate exposure; presence of this module in scan logs against 500/udp indicates active exploitation attempts.
  • ·Only devices configured to accept IKEv1 security negotiation requests are exploitable; IKEv2-only configurations are not affected.
  • ·There are no workarounds that address this vulnerability; only vendor software updates remediate it.
  • ·Affected platforms span Cisco IOS 12.2–12.4 and 15.0–15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x–5.2.x, and PIX before 7.0; scope is broad across Cisco network infrastructure.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.