CVE-2016-6366
KEV PoC ×3massSNMP Buffer Overflow RCE (EXTRABACON) in Cisco ASA, PIX, and FWSM Firewalls
CISA: Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
CVE-2016-6366, known as EXTRABACON (Cisco Bug ID CSCva92151), is a classic buffer overflow (CWE-120) in the SNMP processing of Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3, which runs on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices. A remote, authenticated attacker who knows the device's SNMP credentials (community string or SNMP user) can send crafted IPv4 SNMP packets that trigger the overflow and execute arbitrary code on the firewall, yielding full device control (CVSS 3.1: 8.8, high impact to confidentiality, integrity, and availability). Because these firewalls typically sit at the network perimeter, compromise gives attackers a chokepoint for traffic interception and further lateral movement, so any organization running affected ASA/PIX/FWSM software with SNMP enabled and reachable is at risk. A public exploit was released in 2016 in connection with the Shadow Brokers disclosures of Equation Group tooling, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild. The high EPSS score of 87.6% (100th percentile) combined with the KEV listing indicates elevated near-term exploitation risk, making patching urgent.
What to do: Upgrade Cisco ASA Software to a fixed release for Bug ID CSCva92151 per Cisco's security advisory (all versions through 9.4.2.3 are affected), and apply the corresponding vendor fixes for ASA 1000V, PIX, and FWSM as required by the CISA KEV listing. As interim mitigation, restrict SNMP access to trusted management hosts via ACLs, disable SNMP where unused, prefer SNMPv3 with strong credentials over v1/v2c community strings, and review devices for indicators of compromise such as unexplained configuration changes or added user accounts.
| Cisco Adaptive Security Appliance (ASA) Software | all versions through 9.4.2.3 (at time of disclosure; runs on ASA 5500, ASA 5500-X, ASA Services Module, ASAv, and Firepower 9300 ASA Security Module) |
| Cisco ASA 1000V Cloud Firewall Software | affected per Cisco/CISA; no specific version range provided in source data |
| Cisco PIX Firewall Software | affected per Cisco/CISA; no specific version range provided in source data |
| Cisco Firewall Services Module (FWSM) Software | affected per Cisco/CISA description; no specific version range provided in source data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.
- Affected
- Cisco Adaptive Security Appliance (ASA)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- pix firewall software, adaptive security appliance software, asa 1000v cloud firewall software
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H