CVE-2016-6366
Summary
| CVE | CVE-2016-6366 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-08-18 18:59:00 UTC |
| Updated | 2023-08-15 14:52:00 UTC |
| Description | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON. |
Risk And Classification
EPSS: 0.913890000 probability, percentile 0.996550000 (date 2026-04-01)
CISA KEV: Listed on 2022-05-24; due 2022-06-14; ransomware use Unknown
Problem Types: CWE-119
CISA Known Exploited Vulnerability
| Vendor | Cisco |
|---|---|
| Product | Adaptive Security Appliance (ASA) |
| Name | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2016-6366 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| zerosum0x0: Reverse Engineering Cisco ASA for EXTRABACON Offsets | MISC | zerosum0x0.blogspot.com | Exploit, Technical Description |
| Cisco ASA 8.x - 'EXTRABACON' Authentication Bypass - Hardware remote Exploit | EXPLOIT-DB | www.exploit-db.com | |
| The Shadow Brokers EPICBANANA and EXTRABACON Exploits | CONFIRM | blogs.cisco.com | Press/Media Coverage, Vendor Advisory |
| Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| Cisco Adaptive Security Appliance Products CVE-2016-6366 Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| Cisco Event Response: Cisco ASA and IOS Vulnerabilities | CONFIRM | tools.cisco.com | Vendor Advisory |
| Cisco ASA SNMP Buffer Overflow Lets Remote Users Deny Service or Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Page not found · GitHub · GitHub | MISC | github.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.