CVE-2016-6415: Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-05-19. EPSS: 87.7% chance of exploitation in the next 30 days.

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

Affected products

  • Cisco IOS: from 12.2, up to and including 12.4; from 15.0, up to and including 15.6
  • Cisco IOS XE: up to and including 3.18s
  • Cisco IOS XR: from 4.3.0, up to and including 4.3.4; from 5.0.0, before 5.3.0 (fixed in 5.3.0)

Published 2016-09-19. Last modified 2026-06-17.