Cisco IOS, IOS XE and IOS XR IKEv1 Vulnerability
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability was identified in Cisco IOS, IOS XE and IOS XR, which could allow a remote attacker to obtain memory contents on the target system.
Impact
- Information Disclosure
System / Technologies affected
- Cisco IOS XR 4.3.x
- Cisco IOS XR 5.0.x
- Cisco IOS XR 5.1.x
- Cisco IOS XR 5.2.x
[update on 11-OCT-2016] Cisco has released a IOS Software Checker which allows user to check if their software version is affected:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1
Solutions
- Vulnerability has no patch available
[update on 11-OCT-2016] User can use the IOS Software Checker to check if the first fix is available.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1
Vulnerability Identifier
Source
Related Link
Share with