ZeroHour

CVE-2016-6366

KEV PoC ×3mass

SNMP Buffer Overflow RCE (EXTRABACON) in Cisco ASA, PIX, and FWSM Firewalls

CISA: Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2016-6366, known as EXTRABACON (Cisco Bug ID CSCva92151), is a classic buffer overflow (CWE-120) in the SNMP processing of Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3, which runs on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices. A remote, authenticated attacker who knows the device's SNMP credentials (community string or SNMP user) can send crafted IPv4 SNMP packets that trigger the overflow and execute arbitrary code on the firewall, yielding full device control (CVSS 3.1: 8.8, high impact to confidentiality, integrity, and availability). Because these firewalls typically sit at the network perimeter, compromise gives attackers a chokepoint for traffic interception and further lateral movement, so any organization running affected ASA/PIX/FWSM software with SNMP enabled and reachable is at risk. A public exploit was released in 2016 in connection with the Shadow Brokers disclosures of Equation Group tooling, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild. The high EPSS score of 87.6% (100th percentile) combined with the KEV listing indicates elevated near-term exploitation risk, making patching urgent.

What to do: Upgrade Cisco ASA Software to a fixed release for Bug ID CSCva92151 per Cisco's security advisory (all versions through 9.4.2.3 are affected), and apply the corresponding vendor fixes for ASA 1000V, PIX, and FWSM as required by the CISA KEV listing. As interim mitigation, restrict SNMP access to trusted management hosts via ACLs, disable SNMP where unused, prefer SNMPv3 with strong credentials over v1/v2c community strings, and review devices for indicators of compromise such as unexplained configuration changes or added user accounts.

Affected
Cisco Adaptive Security Appliance (ASA) Softwareall versions through 9.4.2.3 (at time of disclosure; runs on ASA 5500, ASA 5500-X, ASA Services Module, ASAv, and Firepower 9300 ASA Security Module)
Cisco ASA 1000V Cloud Firewall Softwareaffected per Cisco/CISA; no specific version range provided in source data
Cisco PIX Firewall Softwareaffected per Cisco/CISA; no specific version range provided in source data
Cisco Firewall Services Module (FWSM) Softwareaffected per Cisco/CISA description; no specific version range provided in source data
Estimated exposure
mass≈1M+ deployed ASA/PIX/FWSM devices (multi-million-unit ASA installed base; historically tens of thousands of ASA management interfaces exposed on the public… — Cisco ASA/PIX was the flagship enterprise perimeter firewall for roughly a decade with a multi-million-unit installed base, and public internet scans have long shown tens of thousands of ASA devices exposing management services; SNMP is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

CISA Known Exploited Vulnerability
Affected
Cisco Adaptive Security Appliance (ASA)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
pix firewall software, adaptive security appliance software, asa 1000v cloud firewall software
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news