CVE-2016-6367

Cisco Adaptive Security Appliance (ASA): CLI Remote Code Execution

As of , CVE-2016-6367 in Cisco Adaptive Security Appliance (ASA) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 24 May 2022
US federal deadline
14 June 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.23Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.02 on 24 May 2022EPSS on the day CISA listed it.
Public exploit
1 Exploit-DB entry
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

CISA's description

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

The CVE record's description, from cisco

CVE published
18 August 2016
Assigned by
cisco
CVSS
7.8 High (CVSS 3.1, from CISA-ADP)
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 40271).
  3. CISA added it to its list of exploited vulnerabilities.
  4. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Adaptive Security Appliance (ASA): other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2016-6366SNMP Buffer OverflowCisco Adaptive Security Appliance (ASA)Patch this weekMetasploit module; EPSS 0.880.88
CVE-2018-0296Denial-of-ServiceCisco Adaptive Security Appliance (ASA)Patch this weekMetasploit module; EPSS 0.990.99
CVE-2014-2120Cross-Site Scripting (XSS)Cisco Adaptive Security Appliance (ASA)Patch soon0.23

Read further