CVE-2016-6423
published 2016-10-05CVE-2016-6423: The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.22%
65.6th percentile
The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios_and_ios_xe_ikev2 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.3MEDIUMAV:N/AC:M/Au:S/C:N/I:N/A:C
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f765-58h8-hwq6: The IKEv2 client and initiator implementations in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2016-6423 [MEDIUM] GHSA-f765-58h8-hwq6: The IKEv2 client and initiator implementations in Cisco IOS 15
The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.
Cisco
Cisco IOS and IOS XE IKEv2 Denial of Service Vulnerability
vendor_cisco·2016-10-05·CVSS 6.3
CVE-2016-6423 [MEDIUM] CWE-399 Cisco IOS and IOS XE IKEv2 Denial of Service Vulnerability
Cisco IOS and IOS XE IKEv2 Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange version 2 (IKEv2) code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause a reload of the affected device.
The vulnerability is due to improper handling of crafted IKEv2 packets. The vulnerability applies only to IKEv2 devices acting as clients or IKEv2 initiators. An attacker could exploit this vulnerability by sending crafted packets to the affected devices. An attacker, however, would need to be able to force the affected device to connect to a rogue IKEv2 server under its control. An exploit could allow the attacker to cause a reload of the affected system.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate
Cisco
Cisco IOS and IOS XE IKEv2 Denial of Service Vulnerability
vendor_cisco
CVE-2016-6423 Cisco IOS and IOS XE IKEv2 Denial of Service Vulnerability
CVE-2016-6423: Cisco IOS and IOS XE IKEv2 Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange version 2 (IKEv2) code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause a reload of the affected device. The vulnerability is due to improper handling of crafted IKEv2 packets. The vulnerability applies only to IKEv2 devices acting as clients or IKEv2 initiators. An attacker could exploit this vulnerability by sending crafted packets to the affected devices. An attacker, however, would need to be able to force the affected device to connect to a rogue IKEv2 server under its control. An exploit could allow the attacker to cause a reload of the affected system. Cisco has released software updates that address this vulnerability.
CWE: CWE-399,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ios-ikevhttp://www.securityfocus.com/bid/93411http://www.securitytracker.com/id/1036955http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ios-ikevhttp://www.securityfocus.com/bid/93411http://www.securitytracker.com/id/1036955
2016-10-05
Published