EXPOSURES › CVE-2016-6415
CVE-2016-6415
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
Cisco's IOS, IOS XR, and IOS XE products contain an information disclosure vulnerability in the IKEv1 security negotiation requests, allowing attackers to retrieve memory contents. This can lead to information disclosure. DIB orgs should ensure strict access controls and apply patches promptly to mitigate this risk.
Shame score — High-severity vulnerability in critical networking software, leading to information disclosure, with a history of high-severity remote code execution vulnerabilities.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |