PatchSiren cyber security CVE debrief
CVE-2016-9216 Cisco CVE debrief
CVE-2016-9216 describes an IKE packet parsing denial-of-service issue in Cisco ASR 5000 Software. A remote, unauthenticated attacker could cause the ipsecmgr process to reload, which can disrupt IPsec-related service handling. The CVE was published on 2017-01-26 and is scored CVSS 3.0 5.3 (Medium).
- Vendor
- Cisco
- Product
- CVE-2016-9216
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-26
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-26
- Advisory updated
- 2026-05-13
Who should care
Network and security teams running Cisco ASR 5000 Software, especially environments that rely on IPsec/IKE services and have exposure to untrusted networks or peers.
Technical summary
NVD lists the weakness as CWE-399 and the CVSS vector as CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L. That indicates a network-reachable issue requiring no privileges or user interaction, with availability impact only. The affected product versions listed in the source corpus include multiple Cisco ASR 5000 releases such as 20.0.0, 20.0.v0, 20.1.0, 20.1.a0, 20.1.v0, and 21.0.0. Cisco advisory references are present in the NVD record, including CSCuy06917, CSCuy45036, and CSCuy59525.
Defensive priority
Medium. The issue is remotely reachable and unauthenticated, but the reported impact is process reload and availability loss rather than confidentiality or integrity compromise.
Recommended defensive actions
- Confirm whether Cisco ASR 5000 Software is deployed and map each instance to the affected release list in the CVE record.
- Prioritize upgrades to a fixed Cisco release listed in the source corpus for the installed train.
- Review exposure of IKE/IPsec-facing interfaces and restrict unnecessary network access to the device where operationally possible.
- Monitor for unexpected ipsecmgr reloads or related service interruptions and alert on repeated reload patterns.
- Use the Cisco vendor advisory reference and NVD entry to validate the exact fixed build for each deployment.
Evidence notes
This debrief is based only on the supplied NVD/CVE corpus and the listed Cisco references. The CVE description states that an unauthenticated remote attacker can cause the ipsecmgr process to reload. NVD metadata provides the CVSS score, vector, CWE-399 classification, and vulnerable CPEs for Cisco ASR 5000 Software. The record was published on 2017-01-26; the later modified timestamp in the source data is a record update time, not the vulnerability date.
Official resources
-
CVE-2016-9216 CVE record
CVE.org
-
CVE-2016-9216 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
- Source reference
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Publicly disclosed in the CVE record on 2017-01-26. The source corpus shows later record modification on 2026-05-13, which should not be treated as the issue date.