← Back

CVE-2016-6415

nvd nist
Published: Sep 19, 2016Modified: Apr 22, 2026CISA KEV

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

Affected (5)

Products: Cisco: Ios, Ios Xe, Ios Xr
3 products
Ios
Ios Xe
Ios Xr
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
From 12.2 to 12.4
From 15.0 to 15.6
Up to 3.18s
Cisco
From 4.3.0 to 4.3.4
From 5.0.0 to 5.3.0

References (7)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.