SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-6366

Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

KEVHIGH 8.8EPSS 87.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 14 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
87.56% probability · 100th percentile
CISA KEV
Listed 24 May 2022 · due 14 June 2022
Weakness
CWE-120
Affected
cisco/pix firewall software · cisco/adaptive security appliance software · cisco/asa 1000v cloud firewall software
Source
psirt@cisco.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-6366

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.