CVE-2016-6423: Cisco IOS

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.

Affected products

  • Cisco IOS: version 15.5(3)m only

Published 2016-10-05. Last modified 2026-06-17.