← Vulnerability feed

Vulnerability record · CVE-2016-6366 · published 18 August 2016

CVE-2016-6366: Cisco ASA SNMP buffer overflow allows remote code execution

Cisco · Pix Firewall Software

Cisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote authenticated user can trigger it to run arbitrary code on the device, which is a network security appliance sitting on the perimeter. The flaw is publicly known as EXTRABACON and is listed in CISA's Known Exploited Vulnerabilities catalog.

8.8 CVSS 3.1 High CISA KEV since 24 May 2022 EPSS 88% · top 0.2% CWE-120 · Classic buffer overflow
8.8CVSS 3.1 base score, v2 8.5
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
17References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a remotely reachable pre-auth-adjacent buffer overflow on perimeter security appliances, is listed in CISA KEV, and has a very high EPSS score with public exploit code.

What it is

Cisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote authenticated user can trigger it to run arbitrary code on the device, which is a network security appliance sitting on the perimeter. The flaw is publicly known as EXTRABACON and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

Successful exploitation gives the attacker arbitrary code execution on the ASA with the privileges of the affected SNMP service, allowing full compromise of the appliance and any traffic or credentials it handles. Because the device is a perimeter firewall/VPN concentrator, that access can be used to pivot into protected networks.

Attack surface

Reachable over the network via IPv4 SNMP packets sent to the device; the CVSS vector (AV:N/PR:L/UI:N) indicates the attacker must be authenticated but no user interaction is required. SNMP access must be enabled and reachable for the crafted packets to be processed.

Exploitation

The vulnerability is in CISA KEV (added 2022-05-24) and has an EPSS 30-day probability of 0.876 (99.7th percentile), indicating active exploitation is expected. Multiple references are tagged Exploit, including public exploit code and a technical reverse-engineering writeup.

What to do

  • Upgrade ASA/PIX/FWSM software to a fixed release per the Cisco advisory cisco-sa-20160817-asa-snmp; this is the only complete fix.
  • If patching cannot be done immediately, disable SNMP on the affected devices or restrict SNMP access to trusted management hosts only.
  • Replace SNMPv1/v2c with SNMPv3 and strong credentials where SNMP must remain enabled.
  • Segment and firewall management interfaces so SNMP is not reachable from untrusted networks.
  • Monitor Cisco advisories and CISA KEV for updated guidance and verify the fixed version is actually running after upgrade.

Detection

  • Alert on SNMP traffic to ASA/PIX/FWSM management addresses from hosts outside the approved management subnet.
  • Inspect device logs and SNMP service logs for malformed or oversized SNMP requests and unexpected process crashes or reloads.
  • Hunt for unexpected configuration changes, new local accounts, or anomalous outbound connections originating from the firewall appliance.
  • Correlate ASA syslog events with known EXTRABACON exploitation indicators and review for repeated failed SNMP authentication attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-6366 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.cisco.com/security/shadow-brokers ExploitPress/Media CoverageVendor Advisory
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-snmp Vendor Advisory
http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516 Vendor Advisory
http://www.securityfocus.com/bid/92521 Broken LinkNot ApplicableThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036637 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40258.zip Broken LinkExploit
https://www.exploit-db.com/exploits/40258/ Third Party AdvisoryVDB Entry
https://zerosum0x0.blogspot.com/2016/09/reverse-engineering-cisco-asa-for.html ExploitTechnical Description
http://blogs.cisco.com/security/shadow-brokers ExploitPress/Media CoverageVendor Advisory
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-snmp Vendor Advisory
http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516 Vendor Advisory
http://www.securityfocus.com/bid/92521 Broken LinkNot ApplicableThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036637 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40258.zip Broken LinkExploit
https://www.exploit-db.com/exploits/40258/ Third Party AdvisoryVDB Entry
https://zerosum0x0.blogspot.com/2016/09/reverse-engineering-cisco-asa-for.html ExploitTechnical Description
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6366 US Government Resource

Track CVE-2016-6366 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed7.5CVE-2020-3452Cisco ASA and FTD web services path traversal file readCisco ASA and FTD web services fail to validate URL input, allowing directory traversal sequences in HTTP requests to read files inside the web servi…KEVEPSS 100%analysed7.5CVE-2020-3259Cisco ASA and FTD web services memory disclosure via crafted URLCisco ASA and FTD web services interfaces mishandle buffer tracking when parsing invalid URLs, allowing memory contents to be read. The flaw affects …KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2016-6366), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.