ZeroHour

CVE-2016-6367

KEV PoC ×2mass

Command Injection in Cisco ASA CLI Allows Authenticated Local DoS or RCE

CISA: Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
23%p98
Published
()
KEV added
AI analysis

CVE-2016-6367 is a command injection flaw (CWE-77) in the command-line interface (CLI) parser of Cisco Adaptive Security Appliance (ASA) software. An authenticated, local attacker who submits crafted input to CLI commands can trigger the flaw, causing a denial-of-service condition on the appliance or, potentially, execution of arbitrary code. Successful code execution would give an attacker control over an ASA device, which typically sits at the network edge handling firewalling and VPN traffic. Any organization running affected Cisco ASA software is in scope; the source data does not specify affected or fixed version ranges, so administrators should consult Cisco's advisory for exact releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-24 (ransomware use unknown), and EPSS assigns a 22.6% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

What to do: Apply Cisco's fixed ASA software releases per the vendor advisory, as required by CISA's KEV listing; because specific fixed versions are not provided in the source data, check Cisco's advisory for CVE-2016-6367 for the correct upgrade target. Until patched, restrict CLI access to trusted, authenticated administrators and watch for unexpected device reloads. Inventory all ASA appliances and verify none remain unpatched.

Affected
Cisco Adaptive Security Appliance (ASA)
Estimated exposure
masslikely hundreds of thousands of deployed Cisco ASA appliances (exact count unknown) — Cisco ASA is a mass-deployed enterprise firewall/VPN appliance line, and public internet scans have historically found on the order of hundreds of thousands of internet-exposed ASA devices, though the source data provides no direct counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

CISA Known Exploited Vulnerability
Affected
Cisco Adaptive Security Appliance (ASA)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
adaptive security appliance software
Weakness
CWE-77
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news