CVE-2016-6367 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 22.6% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-14.
Description
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 22.58% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | yes — remediate by 2022-06-14 |
| Public exploit | yes |
| Published | 2016-08-18 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-05-24 |
| Due | 2022-06-14 |
| Vendor / product | Cisco / Adaptive Security Appliance (ASA) |
| Ransomware use | none reported |
Affected (30)
| Vendor | Product |
|---|---|
| cisco | adaptive security appliance software |
| cisco | asa 5500 |
| cisco | asa 5500 csc-ssm |
| cisco | asa 5500-x |
| cisco | asa 5505 |
| cisco | asa 5506-x |
| cisco | asa 5506h-x |
| cisco | asa 5506w-x |
| cisco | asa 5508-x |
| cisco | asa 5510 |
| cisco | asa 5512-x |
| cisco | asa 5515-x |
| cisco | asa 5516-x |
| cisco | asa 5520 |
| cisco | asa 5525-x |
| cisco | asa 5540 |
| cisco | asa 5545-x |
| cisco | asa 5550 |
| cisco | asa 5555-x |
| cisco | asa 5580 |
| cisco | asa 5585-x |
| cisco | firewall services module |
| cisco | pix firewall 501 |
| cisco | pix firewall 506 |
| cisco | pix firewall 506e |
| cisco | pix firewall 515 |
| cisco | pix firewall 515e |
| cisco | pix firewall 520 |
| cisco | pix firewall 525 |
| cisco | pix firewall 535 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco ASA / PIX - 'EPICBANANA' Local Privilege Escalation | 2016-08-19 |
References
- http://blogs.cisco.com/security/shadow-brokers
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-cli
- http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516
- http://www.securityfocus.com/bid/92520
- http://www.securitytracker.com/id/1036636
- https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40271.zip
- https://www.exploit-db.com/exploits/40271/
- http://blogs.cisco.com/security/shadow-brokers
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-cli
- http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516
- http://www.securityfocus.com/bid/92520
- http://www.securitytracker.com/id/1036636
- https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40271.zip
- https://www.exploit-db.com/exploits/40271/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6367
→ the Explorer · watch your stack · NVD