Junglewise Threat Intelligence

CVE-2016-6367: Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

CVE-2016-6367 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-24

Technologies: Cisco Adaptive Security Appliance (ASA), Cisco Firepower Threat Defense (FTD), Cisco Adaptive Security Appliance (ASA) Software. Vendors: Cisco.

Executive brief

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software allows an authenticated, local attacker to gain elevated privileges or execute arbitrary code via invalid CLI commands. The flaw, also known as EPICBANANA, stems from improper neutralization of special elements within the CLI parser.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software Before 8.4(1)
  • Cisco PIX
  • Cisco FWSM

Timeline

  • 2016-08-17: disclosed: Initial Cisco security advisory published
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-24: exploited: Confirmed as exploited in the wild by CISA

Related threats