cbcvebase.
CVE-2016-6366
published 2016-08-18

CVE-2016-6366: Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower…

PriorityP194high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-06-14
Exploited in the wild
EPSS
87.56%
99.7th percentile
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

Affected

10 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance
ciscoadaptive_security_appliance_software>= 7.2.1 < 9.0.4.409.0.4.40
ciscoadaptive_security_appliance_software>= 9.1.1 < 9.1.7\(9\)9.1.7\(9\)
ciscoadaptive_security_appliance_software>= 9.2.0 < 9.2.4\(14\)9.2.4\(14\)
ciscoadaptive_security_appliance_software>= 9.3.0 < 9.3.3\(10\)9.3.3\(10\)
ciscoadaptive_security_appliance_software>= 9.4.0.115 < 9.4.3\(8\)9.4.3\(8\)
ciscoadaptive_security_appliance_software9.5.0 – 9.5\(3\)
ciscoadaptive_security_appliance_software>= 9.6.0 < 9.6.1\(11\)9.6.1\(11\)
ciscoasa_1000v_cloud_firewall_software
ciscoasa_1000v_cloud_firewall_software

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/40258.zip
port161/udp (SNMP)
  • The exploit (EXTRABACON) requires SNMP read community string access and targets SNMP-enabled interfaces. Monitor for crafted/anomalous SNMPv1/v2c/v3 packets directed at ASA management interfaces, especially from unexpected sources.
  • The exploit requires SSH port to be accessible in addition to SNMP. Restrict SNMP access to trusted management hosts and block SNMP from untrusted networks as a detection/prevention chokepoint.
  • The vulnerability is only triggerable via IPv4 traffic. IPv6 SNMP traffic to ASA is not an attack vector for this CVE.
  • ·The vulnerability affects all SNMP versions (1, 2c, and 3) when SNMP is enabled. Disabling SNMP entirely is the most effective workaround if not required.
  • ·Only traffic directed to the ASA itself (not transit traffic) can exploit this vulnerability. Ensure SNMP is not exposed to untrusted networks.
  • ·The exploit requires knowledge of the SNMP community string (v1/v2c) or valid credentials (v3). Rotating community strings and using SNMPv3 with strong credentials reduces exposure but does not eliminate it on unpatched systems.
  • ·The vulnerability affects systems in both routed and transparent firewall mode, and in single or multiple context mode — all configurations are at risk.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.