CVE-2016-6366 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 87.6% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-14.
Description
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 87.57% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | yes — remediate by 2022-06-14 |
| Public exploit | yes |
| Published | 2016-08-18 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability |
|---|---|
| Added | 2022-05-24 |
| Due | 2022-06-14 |
| Vendor / product | Cisco / Adaptive Security Appliance (ASA) |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| cisco | 7604 |
| cisco | 7606-s |
| cisco | 7609-s |
| cisco | 7613-s |
| cisco | adaptive security appliance software |
| cisco | asa 5500 |
| cisco | asa 5500 csc-ssm |
| cisco | asa 5500-x |
| cisco | asa 5505 |
| cisco | asa 5506-x |
| cisco | asa 5506h-x |
| cisco | asa 5506w-x |
| cisco | asa 5508-x |
| cisco | asa 5510 |
| cisco | asa 5512-x |
| cisco | asa 5515-x |
| cisco | asa 5516-x |
| cisco | asa 5520 |
| cisco | asa 5525-x |
| cisco | asa 5540 |
| cisco | asa 5545-x |
| cisco | asa 5550 |
| cisco | asa 5555-x |
| cisco | asa 5580 |
| cisco | asa 5585-x |
| cisco | catalyst 6500 |
| cisco | catalyst 6500-e |
| cisco | catalyst 6503-e |
| cisco | catalyst 6504-e |
| cisco | catalyst 6506-e |
| cisco | catalyst 6509-e |
| cisco | pix firewall 501 |
| cisco | pix firewall 506 |
| cisco | pix firewall 506e |
| cisco | pix firewall 515 |
| cisco | pix firewall 515e |
| cisco | pix firewall 520 |
| cisco | pix firewall 525 |
| cisco | pix firewall 535 |
| cisco | pix firewall software |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco ASA 8.x - 'EXTRABACON' Authentication Bypass | 2016-08-18 |
References
- http://blogs.cisco.com/security/shadow-brokers
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-snmp
- http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516
- http://www.securityfocus.com/bid/92521
- http://www.securitytracker.com/id/1036637
- https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40258.zip
- https://www.exploit-db.com/exploits/40258/
- https://zerosum0x0.blogspot.com/2016/09/reverse-engineering-cisco-asa-for.html
- http://blogs.cisco.com/security/shadow-brokers
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-snmp
- http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516
- http://www.securityfocus.com/bid/92521
- http://www.securitytracker.com/id/1036637
- https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40258.zip
- https://www.exploit-db.com/exploits/40258/
- https://zerosum0x0.blogspot.com/2016/09/reverse-engineering-cisco-asa-for.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6366
→ the Explorer · watch your stack · NVD