Vulnerable Products:
This vulnerability affects Cisco products if they are running a vulnerable release of Cisco ASA, FTD, IOS, or IOS XE Software and have the IKEv2 protocol enabled.
Note: G-IKEv2 is not affected by this vulnerability.
For information about which Cisco software releases are vulnerable, see the Fixed Software ["#fs"] section of this advisory. Determine the Cisco ASA or FTD Software IKEv2 Configuration To determine whether IKEv2 is enabled on an interface, use the show running-config crypto ikev2 | include enable CLI command. If that command returns output, IKEv2 is enabled on at least one interface. The following example shows the output of the show running-config crypto ikev2 | include enable command on a device that has IKEv2 enabled on the outside interface:
device# show running-config crypto ikev2 | include enable crypto ikev2 enable outside
If the command returns no output, the device is not affected by this vulnerability.
Note: For devices that are running Cisco FTD Software, the command prompt will end with > and not #. Determine the Cisco IOS or IOS XE Software IKEv2 Configuration
To determine whether IKE processing is enabled, use the show ip sockets or show udp EXEC command in the CLI. These commands will show the same output for both IKEv1 and IKEv2 because both use the same port numbers. If UDP port 500, UDP port 848, UDP port 4500, or UDP port 4848 is open on a device, the device is processing IKE packets.
The following example shows the output of the show udp command on a device that is processing IKE packets on UDP port 500 and UDP port 4500, using either IPv4 or IPv6:
router# show udp Proto Remote Port Local Port In Out Stat TTY OutputIF 17 --listen-- 192.168.130.21 500 0 0 1001011 0 17(v6) --listen-- UNKNOWN 500 0 0 1020011 0 17 --listen--...
12.2(6)I112.4(22)MD12.4(22)MD112.4(22)MD212.4(22)MDA12.4(22)MDA112.4(22)MDA212.4(22)MDA312.4(22)MDA412.4(22)MDA5+721 more16.1.116.1.216.1.316.10.116.10.1a16.10.1b16.10.1c16.10.1d16.10.1e16.10.1f+450 moreExploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:NI:NA:H8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H