8.8

CVE-2016-6366

Warning
Media report
Exploit

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

Data is provided by the National Vulnerability Database (NVD)
CiscoPix Firewall Software Version-
   CiscoPix Firewall 501 Version-
   CiscoPix Firewall 506 Version-
   CiscoPix Firewall 506e Version-
   CiscoPix Firewall 515 Version-
   CiscoPix Firewall 515e Version-
   CiscoPix Firewall 520 Version-
   CiscoPix Firewall 525 Version-
   CiscoPix Firewall 535 Version-
CiscoAdaptive Security Appliance Software Version >= 7.2.1 < 9.0.4.40
   Cisco7604 Version-
   Cisco7606-s Version-
   Cisco7609-s Version-
   Cisco7613-s Version-
   CiscoAsa 5500 Version-
   CiscoAsa 5500-x Version-
   CiscoAsa 5500 Csc-ssm Version-
   CiscoAsa 5505 Version-
   CiscoAsa 5506-x Version-
   CiscoAsa 5506h-x Version-
   CiscoAsa 5506w-x Version-
   CiscoAsa 5508-x Version-
   CiscoAsa 5510 Version-
   CiscoAsa 5512-x Version-
   CiscoAsa 5515-x Version-
   CiscoAsa 5516-x Version-
   CiscoAsa 5520 Version-
   CiscoAsa 5525-x Version-
   CiscoAsa 5540 Version-
   CiscoAsa 5545-x Version-
   CiscoAsa 5550 Version-
   CiscoAsa 5555-x Version-
   CiscoAsa 5580 Version-
   CiscoAsa 5585-x Version-
   CiscoCatalyst 6500 Version-
   CiscoCatalyst 6500-e Version-
   CiscoCatalyst 6503-e Version-
   CiscoCatalyst 6504-e Version-
   CiscoCatalyst 6506-e Version-
   CiscoCatalyst 6509-e Version-
   CiscoCatalyst 6509-neb-a Version-
   CiscoCatalyst 6509-v-e Version-
   CiscoCatalyst 6513 Version-
   CiscoCatalyst 6513-e Version-
CiscoAdaptive Security Appliance Software Version >= 9.1.1 < 9.1.7\(9\)
   Cisco7604 Version-
   Cisco7606-s Version-
   Cisco7609-s Version-
   Cisco7613-s Version-
   CiscoAsa 5500 Version-
   CiscoAsa 5500-x Version-
   CiscoAsa 5500 Csc-ssm Version-
   CiscoAsa 5505 Version-
   CiscoAsa 5506-x Version-
   CiscoAsa 5506h-x Version-
   CiscoAsa 5506w-x Version-
   CiscoAsa 5508-x Version-
   CiscoAsa 5510 Version-
   CiscoAsa 5512-x Version-
   CiscoAsa 5515-x Version-
   CiscoAsa 5516-x Version-
   CiscoAsa 5520 Version-
   CiscoAsa 5525-x Version-
   CiscoAsa 5540 Version-
   CiscoAsa 5545-x Version-
   CiscoAsa 5550 Version-
   CiscoAsa 5555-x Version-
   CiscoAsa 5580 Version-
   CiscoAsa 5585-x Version-
   CiscoCatalyst 6500 Version-
   CiscoCatalyst 6500-e Version-
   CiscoCatalyst 6503-e Version-
   CiscoCatalyst 6504-e Version-
   CiscoCatalyst 6506-e Version-
   CiscoCatalyst 6509-e Version-
   CiscoCatalyst 6509-neb-a Version-
   CiscoCatalyst 6509-v-e Version-
   CiscoCatalyst 6513 Version-
   CiscoCatalyst 6513-e Version-
CiscoAdaptive Security Appliance Software Version >= 9.2.0 < 9.2.4\(14\)
   Cisco7604 Version-
   Cisco7606-s Version-
   Cisco7609-s Version-
   Cisco7613-s Version-
   CiscoAsa 5500 Version-
   CiscoAsa 5500-x Version-
   CiscoAsa 5500 Csc-ssm Version-
   CiscoAsa 5505 Version-
   CiscoAsa 5506-x Version-
   CiscoAsa 5506h-x Version-
   CiscoAsa 5506w-x Version-
   CiscoAsa 5508-x Version-
   CiscoAsa 5510 Version-
   CiscoAsa 5512-x Version-
   CiscoAsa 5515-x Version-
   CiscoAsa 5516-x Version-
   CiscoAsa 5520 Version-
   CiscoAsa 5525-x Version-
   CiscoAsa 5540 Version-
   CiscoAsa 5545-x Version-
   CiscoAsa 5550 Version-
   CiscoAsa 5555-x Version-
   CiscoAsa 5580 Version-
   CiscoAsa 5585-x Version-
   CiscoCatalyst 6500 Version-
   CiscoCatalyst 6500-e Version-
   CiscoCatalyst 6503-e Version-
   CiscoCatalyst 6504-e Version-
   CiscoCatalyst 6506-e Version-
   CiscoCatalyst 6509-e Version-
   CiscoCatalyst 6509-neb-a Version-
   CiscoCatalyst 6509-v-e Version-
   CiscoCatalyst 6513 Version-
   CiscoCatalyst 6513-e Version-
CiscoAdaptive Security Appliance Software Version >= 9.3.0 < 9.3.3\(10\)
   Cisco7604 Version-
   Cisco7606-s Version-
   Cisco7609-s Version-
   Cisco7613-s Version-
   CiscoAsa 5500 Version-
   CiscoAsa 5500-x Version-
   CiscoAsa 5500 Csc-ssm Version-
   CiscoAsa 5505 Version-
   CiscoAsa 5506-x Version-
   CiscoAsa 5506h-x Version-
   CiscoAsa 5506w-x Version-
   CiscoAsa 5508-x Version-
   CiscoAsa 5510 Version-
   CiscoAsa 5512-x Version-
   CiscoAsa 5515-x Version-
   CiscoAsa 5516-x Version-
   CiscoAsa 5520 Version-
   CiscoAsa 5525-x Version-
   CiscoAsa 5540 Version-
   CiscoAsa 5545-x Version-
   CiscoAsa 5550 Version-
   CiscoAsa 5555-x Version-
   CiscoAsa 5580 Version-
   CiscoAsa 5585-x Version-
   CiscoCatalyst 6500 Version-
   CiscoCatalyst 6500-e Version-
   CiscoCatalyst 6503-e Version-
   CiscoCatalyst 6504-e Version-
   CiscoCatalyst 6506-e Version-
   CiscoCatalyst 6509-e Version-
   CiscoCatalyst 6509-neb-a Version-
   CiscoCatalyst 6509-v-e Version-
   CiscoCatalyst 6513 Version-
   CiscoCatalyst 6513-e Version-
CiscoAdaptive Security Appliance Software Version >= 9.4.0.115 < 9.4.3\(8\)
   Cisco7604 Version-
   Cisco7606-s Version-
   Cisco7609-s Version-
   Cisco7613-s Version-
   CiscoAsa 5500 Version-
   CiscoAsa 5500-x Version-
   CiscoAsa 5500 Csc-ssm Version-
   CiscoAsa 5505 Version-
   CiscoAsa 5506-x Version-
   CiscoAsa 5506h-x Version-
   CiscoAsa 5506w-x Version-
   CiscoAsa 5508-x Version-
   CiscoAsa 5510 Version-
   CiscoAsa 5512-x Version-
   CiscoAsa 5515-x Version-
   CiscoAsa 5516-x Version-
   CiscoAsa 5520 Version-
   CiscoAsa 5525-x Version-
   CiscoAsa 5540 Version-
   CiscoAsa 5545-x Version-
   CiscoAsa 5550 Version-
   CiscoAsa 5555-x Version-
   CiscoAsa 5580 Version-
   CiscoAsa 5585-x Version-
   CiscoCatalyst 6500 Version-
   CiscoCatalyst 6500-e Version-
   CiscoCatalyst 6503-e Version-
   CiscoCatalyst 6504-e Version-
   CiscoCatalyst 6506-e Version-
   CiscoCatalyst 6509-e Version-
   CiscoCatalyst 6509-neb-a Version-
   CiscoCatalyst 6509-v-e Version-
   CiscoCatalyst 6513 Version-
   CiscoCatalyst 6513-e Version-
CiscoAdaptive Security Appliance Software Version >= 9.5.0 <= 9.5\(3\)
   Cisco7604 Version-
   Cisco7606-s Version-
   Cisco7609-s Version-
   Cisco7613-s Version-
   CiscoAsa 5500 Version-
   CiscoAsa 5500-x Version-
   CiscoAsa 5500 Csc-ssm Version-
   CiscoAsa 5505 Version-
   CiscoAsa 5506-x Version-
   CiscoAsa 5506h-x Version-
   CiscoAsa 5506w-x Version-
   CiscoAsa 5508-x Version-
   CiscoAsa 5510 Version-
   CiscoAsa 5512-x Version-
   CiscoAsa 5515-x Version-
   CiscoAsa 5516-x Version-
   CiscoAsa 5520 Version-
   CiscoAsa 5525-x Version-
   CiscoAsa 5540 Version-
   CiscoAsa 5545-x Version-
   CiscoAsa 5550 Version-
   CiscoAsa 5555-x Version-
   CiscoAsa 5580 Version-
   CiscoAsa 5585-x Version-
   CiscoCatalyst 6500 Version-
   CiscoCatalyst 6500-e Version-
   CiscoCatalyst 6503-e Version-
   CiscoCatalyst 6504-e Version-
   CiscoCatalyst 6506-e Version-
   CiscoCatalyst 6509-e Version-
   CiscoCatalyst 6509-neb-a Version-
   CiscoCatalyst 6509-v-e Version-
   CiscoCatalyst 6513 Version-
   CiscoCatalyst 6513-e Version-
CiscoAdaptive Security Appliance Software Version >= 9.6.0 < 9.6.1\(11\)
   Cisco7604 Version-
   Cisco7606-s Version-
   Cisco7609-s Version-
   Cisco7613-s Version-
   CiscoAsa 5500 Version-
   CiscoAsa 5500-x Version-
   CiscoAsa 5500 Csc-ssm Version-
   CiscoAsa 5505 Version-
   CiscoAsa 5506-x Version-
   CiscoAsa 5506h-x Version-
   CiscoAsa 5506w-x Version-
   CiscoAsa 5508-x Version-
   CiscoAsa 5510 Version-
   CiscoAsa 5512-x Version-
   CiscoAsa 5515-x Version-
   CiscoAsa 5516-x Version-
   CiscoAsa 5520 Version-
   CiscoAsa 5525-x Version-
   CiscoAsa 5540 Version-
   CiscoAsa 5545-x Version-
   CiscoAsa 5550 Version-
   CiscoAsa 5555-x Version-
   CiscoAsa 5580 Version-
   CiscoAsa 5585-x Version-
   CiscoCatalyst 6500 Version-
   CiscoCatalyst 6500-e Version-
   CiscoCatalyst 6503-e Version-
   CiscoCatalyst 6504-e Version-
   CiscoCatalyst 6506-e Version-
   CiscoCatalyst 6509-e Version-
   CiscoCatalyst 6509-neb-a Version-
   CiscoCatalyst 6509-v-e Version-
   CiscoCatalyst 6513 Version-
   CiscoCatalyst 6513-e Version-

24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

Vulnerability

A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 90.98% 0.996
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.