Rapid7 Vulnerability & Exploit Database

Cisco ASA: CVE-2016-6366: Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability

Back to Search

Cisco ASA: CVE-2016-6366: Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability

Severity
9
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:C)
Published
08/18/2016
Created
07/25/2018
Added
09/07/2016
Modified
10/21/2021

Description

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

Solution(s)

  • cisco-asa-update-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;