Skip to main content

Cisco IOS, IOS XE and IOS XR IKEv1 Vulnerability

Last Update Date: 11 Oct 2016 Release Date: 19 Sep 2016 3166 Views

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability was identified in Cisco IOS, IOS XE and IOS XR, which could allow a remote attacker to obtain memory contents on the target system.


Impact

  • Information Disclosure

System / Technologies affected

  • Cisco IOS XR 4.3.x
  • Cisco IOS XR 5.0.x
  • Cisco IOS XR 5.1.x
  • Cisco IOS XR 5.2.x

[update on 11-OCT-2016] Cisco has released a IOS Software Checker which allows user to check if their software version is affected:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1


Solutions

  • Vulnerability has no patch available

[update on 11-OCT-2016] User can use the IOS Software Checker to check if the first fix is available.

 

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1


Vulnerability Identifier


Source


Related Link