CVE-2016-6415 is a critical information disclosure vulnerability affecting the IKEv1 implementation in various Cisco IOS, IOS XE, and IOS XR versions, allowing remote attackers to extract sensitive data from device memory via crafted Security Association negotiation requests. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network without authentication, leading to a high impact on confidentiality. This flaw is actively exploited in the wild, as evidenced by its presence in CISA's KEV catalog and available Metasploit modules, garnering significant community discussion and media coverage. Its high EPSS score and FAUCET Risk Score of 100/100 underscore the urgent need for remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2, <= 12.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
>= 15.0, <= 15.6CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
<= 3.18sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* | ||
>= 4.3.0, <= 4.3.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.