Junglewise Threat Intelligence

CVE-2016-6366: Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

CVE-2016-6366 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-24

Technologies: Cisco Adaptive Security Appliance (ASA) Software, Cisco Adaptive Security Appliance (ASA), Cisco Firepower Threat Defense (FTD). Vendors: Cisco.

Executive brief

A buffer overflow vulnerability in the SNMP code of Cisco ASA software allows remote authenticated attackers to execute arbitrary code or cause a system reload via crafted IPv4 SNMP packets. The vulnerability, also known as EXTRABACON, affects multiple Cisco security platforms including ASA 5500, PIX, and Firepower modules.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3
  • Cisco ASA 5500 Series Adaptive Security Appliances
  • Cisco ASA 5500-X Series Next-Generation Firewalls
  • Cisco ASA Services Module
  • Cisco ASA 1000V Cloud Firewall
  • Cisco ASAv
  • Cisco Firepower 9300 ASA Security Module
  • Cisco PIX Firewalls
  • Cisco Firewall Services Module (FWSM)

Timeline

  • 2016-08-17: advisory: Cisco Security Advisory published
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-24: disclosed: NVD publication date

Related threats