peter bassill · operator
$ cve CVE-2016-6367 JSON

CVE-2016-6367 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 22.6% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-14.

Description

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS22.58% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-77
On CISA KEVyes — remediate by 2022-06-14
Public exploityes
Published2016-08-18
Last modified2026-06-17

CISA KEV

NameCisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability
Added2022-05-24
Due2022-06-14
Vendor / productCisco / Adaptive Security Appliance (ASA)
Ransomware usenone reported

Affected (30)

VendorProduct
ciscoadaptive security appliance software
ciscoasa 5500
ciscoasa 5500 csc-ssm
ciscoasa 5500-x
ciscoasa 5505
ciscoasa 5506-x
ciscoasa 5506h-x
ciscoasa 5506w-x
ciscoasa 5508-x
ciscoasa 5510
ciscoasa 5512-x
ciscoasa 5515-x
ciscoasa 5516-x
ciscoasa 5520
ciscoasa 5525-x
ciscoasa 5540
ciscoasa 5545-x
ciscoasa 5550
ciscoasa 5555-x
ciscoasa 5580
ciscoasa 5585-x
ciscofirewall services module
ciscopix firewall 501
ciscopix firewall 506
ciscopix firewall 506e
ciscopix firewall 515
ciscopix firewall 515e
ciscopix firewall 520
ciscopix firewall 525
ciscopix firewall 535

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD