CVE-2016-6366
published 2016-08-18CVE-2016-6366: Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower…
PriorityP194high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-06-14
Exploited in the wild
EPSS
87.56%
99.7th percentile
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | >= 7.2.1 < 9.0.4.40 | 9.0.4.40 |
| cisco | adaptive_security_appliance_software | >= 9.1.1 < 9.1.7\(9\) | 9.1.7\(9\) |
| cisco | adaptive_security_appliance_software | >= 9.2.0 < 9.2.4\(14\) | 9.2.4\(14\) |
| cisco | adaptive_security_appliance_software | >= 9.3.0 < 9.3.3\(10\) | 9.3.3\(10\) |
| cisco | adaptive_security_appliance_software | >= 9.4.0.115 < 9.4.3\(8\) | 9.4.3\(8\) |
| cisco | adaptive_security_appliance_software | 9.5.0 – 9.5\(3\) | — |
| cisco | adaptive_security_appliance_software | >= 9.6.0 < 9.6.1\(11\) | 9.6.1\(11\) |
| cisco | asa_1000v_cloud_firewall_software | — | — |
| cisco | asa_1000v_cloud_firewall_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit (EXTRABACON) requires SNMP read community string access and targets SNMP-enabled interfaces. Monitor for crafted/anomalous SNMPv1/v2c/v3 packets directed at ASA management interfaces, especially from unexpected sources. ↗
- →The exploit requires SSH port to be accessible in addition to SNMP. Restrict SNMP access to trusted management hosts and block SNMP from untrusted networks as a detection/prevention chokepoint. ↗
- →The vulnerability is only triggerable via IPv4 traffic. IPv6 SNMP traffic to ASA is not an attack vector for this CVE. ↗
- ·The vulnerability affects all SNMP versions (1, 2c, and 3) when SNMP is enabled. Disabling SNMP entirely is the most effective workaround if not required. ↗
- ·Only traffic directed to the ASA itself (not transit traffic) can exploit this vulnerability. Ensure SNMP is not exposed to untrusted networks. ↗
- ·The exploit requires knowledge of the SNMP community string (v1/v2c) or valid credentials (v3). Rotating community strings and using SNMPv3 with strong credentials reduces exposure but does not eliminate it on unpatched systems. ↗
- ·The vulnerability affects systems in both routed and transparent firewall mode, and in single or multiple context mode — all configurations are at risk. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
cisa·2022-05-24·CVSS 8.8
CVE-2016-6366 [HIGH] CWE-119 Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
Vulnerability: Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
Affected: Cisco Adaptive Security Appliance (ASA)
A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-6366
Remediation Due Date: 2022-06-14
Cisco
Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability
vendor_cisco·2016-08-17·CVSS 8.5
CVE-2016-6366 [HIGH] CWE-119 Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability
Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code.
The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3) when enabled on a virtual or physical Cisco ASA device. An attacker could exploit this vulnerability by sending crafted SNMP packets to an SNMP-enabled interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. The attack
Cisco
Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability
vendor_cisco
CVE-2016-6366 Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability
CVE-2016-6366: Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3) when enabled on a virtual or physical Cisco ASA device. An attacker could exploit this vulnerability by sending crafted SNMP packets to an SNMP-enabled interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected syste
GHSA
GHSA-pfgh-2mw6-962h: Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9
ghsa_unreviewed·2022-05-17
CVE-2016-6366 [HIGH] CWE-119 GHSA-pfgh-2mw6-962h: Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.
VulnCheck
Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
vulncheck·2016·CVSS 8.8
CVE-2016-6366 [HIGH] CWE-119 Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/ncas/alerts/TA16-250A; https://cisa.gov/news-events/alerts/2015/08/01/recent-email-phishing-campaigns-mitigation-and-response; https://www.dropbox.com/s/buxkfotx1kei0ce/Whitepaper%20Shadow%20Broker%20-%20Equation%20Group%20Hack.pdf?dl=0; http
Suricata
ET EXPLOIT CISCO FIREWALL SNMP Buffer Overflow Extrabacon (CVE-2016-6366)
suricata·2016-08-25·CVSS 8.8
CVE-2016-6366 [HIGH] ET EXPLOIT CISCO FIREWALL SNMP Buffer Overflow Extrabacon (CVE-2016-6366)
ET EXPLOIT CISCO FIREWALL SNMP Buffer Overflow Extrabacon (CVE-2016-6366)
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"ET EXPLOIT CISCO FIREWALL SNMP Buffer Overflow Extrabacon (CVE-2016-6366)"; content:"|06 01 04 01 09 09 83 6B|"; pcre:"/^(?:\x01(?:(?:\x01(?:(?:\x04(?:(?:\x03(?:\x01(?:[\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b])?)?|\x04(?:\x01(?:[\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b])?)?|\x01(?:\x01(?:[\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a])?)?|\x02(?:\x01(?:[\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a])?)?))?|\x01(?:[\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c])?|\x02(?:[\x01\x02\x03\x04])?|\x03(?:[\x01\x02])?))?|\x03(?:(?:\x03(?:\x01(?:\x01(?:[\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e])?)?)?|\x01(?:[\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b
Exploit-DB
Cisco ASA 8.x - 'EXTRABACON' Authentication Bypass
exploitdb·2016-08-18
CVE-2016-6366 Cisco ASA 8.x - 'EXTRABACON' Authentication Bypass
Cisco ASA 8.x - 'EXTRABACON' Authentication Bypass
---
# Exploit Title: Cisco ASA 8.X Authentication Bypass
# Date: 17-08-2016
# Exploit Author: Equation Group
# Vendor Homepage: Cisco
# Software Link: Cisco
# Version: Cisco ASA 8.X
# Tested on: Cisco ASA 8.4.2
# CVE : Not sure
Requirements:
* SNMP read (public) string
* Access to SNMP service
* SSH port accessible
Full Exploit:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/40258.zip
Metasploit
Cisco ASA Authentication Bypass (EXTRABACON)
metasploit
Cisco ASA Authentication Bypass (EXTRABACON)
Cisco ASA Authentication Bypass (EXTRABACON)
This module patches the authentication functions of a Cisco ASA to allow uncredentialed logins. Uses improved shellcode for payload.
Qualys
Mystery Magic Bytes From The Equation Leak | Qualys
blogs_qualys·2016-08-26·CVSS 8.8
[HIGH] Mystery Magic Bytes From The Equation Leak | Qualys
Days ago, a mysterious online group called Shadow Brokers claims to have stolen US “cyber weapons” from a hacking team called Equation Group. These “cyber weapons” contain about a dozen vulnerabilities which are believed to be exploits used by the National Security Agency (NSA). In this blog, I will analyze the shellcode from the Cisco exploit and show its behind-the-scenes behavior.
### Shellcode Analysis
Shellcode is a piece of code which gets executed after a vulnerability is exploited. It is the actual instructions attackers want to run on the victim’s machine. Shellcode here comes from the Cisco SNMP exploit (CVE-2016-6366). Under this leaked exploit of Cisco ASA, there is a folder containing the shellcodes for all listed versions. The version used in this blog is 8.2.1.
Shellcode
Qualys
Mystery Magic Bytes From The Equation Leak | Qualys
blogs_qualys·2016-08-26·CVSS 8.8
[HIGH] Mystery Magic Bytes From The Equation Leak | Qualys
Days ago, a mysterious online group called Shadow Brokers claims to have stolen US “cyber weapons” from a hacking team called Equation Group. These “cyber weapons” contain about a dozen vulnerabilities which are believed to be exploits used by the National Security Agency (NSA). In this blog, I will analyze the shellcode from the Cisco exploit and show its behind-the-scenes behavior.
## Shellcode Analysis
Shellcode is a piece of code which gets executed after a vulnerability is exploited. It is the actual instructions attackers want to run on the victim’s machine. Shellcode here comes from the Cisco SNMP exploit ( CVE-2016-6366 ). Under this leaked exploit of Cisco ASA, there is a folder containing the shellcodes for all listed versions. The version used in this blog is 8.2.1.
Shellcode
http://blogs.cisco.com/security/shadow-brokershttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-snmphttp://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516http://www.securityfocus.com/bid/92521http://www.securitytracker.com/id/1036637https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40258.ziphttps://www.exploit-db.com/exploits/40258/https://zerosum0x0.blogspot.com/2016/09/reverse-engineering-cisco-asa-for.htmlhttp://blogs.cisco.com/security/shadow-brokershttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-snmphttp://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516http://www.securityfocus.com/bid/92521http://www.securitytracker.com/id/1036637https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40258.ziphttps://www.exploit-db.com/exploits/40258/https://zerosum0x0.blogspot.com/2016/09/reverse-engineering-cisco-asa-for.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6366
2016-08-18
Published
2022-05-24
Added to CISA KEV
Exploited in the wild