CVE-2016-6415, also known as BENIGNCERTAIN, is an information disclosure vulnerability in the IKEv1 server implementation of Cisco IOS (12.2-12.4, 15.0-15.6), IOS XE (up to 3.18S), IOS XR (4.3.x, 5.0.x-5.2.x), and PIX (before 7.0). Remote attackers can exploit this flaw by sending a crafted Security Association (SA) negotiation request, which allows them to extract sensitive information from device memory. The vulnerability is tracked by Cisco Bug IDs CSCvb29204 and CSCvb36055.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary scanner module targeting the Cisco IKEv1 Information Disclosure vulnerability (CVE-2016-6415), also known as BENIGNCERTAIN. The module is written in Ruby and is designed to be used within the Metasploit Framework. It sends a crafted ISAKMP (IKEv1) packet (by default, from a provided binary file) to UDP port 500 of a target device running Cisco IOS, IOS XE, or IOS XR. If the target is vulnerable, the device responds with leaked memory contents, which the module processes and displays. The module reports the vulnerability if a leak is detected. The only endpoints involved are the target's UDP port 500 and the local packet file used as the payload. The module is a proof-of-concept for information disclosure and does not provide post-exploitation capabilities.
This repository is a Dockerized Python-based exploit and monitoring tool targeting Cisco devices vulnerable to CVE-2016-6415 (BENIGNCERTAIN). The main exploit logic is in 'benigncertain/benign.py', which crafts and sends a malicious IKEv1 packet over UDP port 500 to the target, causing the device to leak memory. The 'poc.py' script orchestrates the attack, repeatedly invoking the exploit, extracting ASCII strings from the resulting memory dumps, and storing them in a local SQLite database ('details.db'). The process is automated via 'entry.sh', which continuously polls the target and updates the database, allowing for ongoing monitoring and aggregation of leaked data. The repository is structured for ease of use via Docker, with clear separation between the exploit code, orchestration script, and supporting files. The exploit is operational and can be used to harvest sensitive information (such as probable passwords) from affected Cisco devices over time.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.