Vulnerability record · CVE-2016-6366 · published 18 August 2016
CVE-2016-6366: Cisco ASA SNMP buffer overflow allows remote code execution
Cisco · Pix Firewall Software
Cisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote authenticated user can trigger it to run arbitrary code on the device, which is a network security appliance sitting on the perimeter. The flaw is publicly known as EXTRABACON and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a remotely reachable pre-auth-adjacent buffer overflow on perimeter security appliances, is listed in CISA KEV, and has a very high EPSS score with public exploit code.
What it is
Cisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote authenticated user can trigger it to run arbitrary code on the device, which is a network security appliance sitting on the perimeter. The flaw is publicly known as EXTRABACON and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
Successful exploitation gives the attacker arbitrary code execution on the ASA with the privileges of the affected SNMP service, allowing full compromise of the appliance and any traffic or credentials it handles. Because the device is a perimeter firewall/VPN concentrator, that access can be used to pivot into protected networks.
Attack surface
Reachable over the network via IPv4 SNMP packets sent to the device; the CVSS vector (AV:N/PR:L/UI:N) indicates the attacker must be authenticated but no user interaction is required. SNMP access must be enabled and reachable for the crafted packets to be processed.
Exploitation
The vulnerability is in CISA KEV (added 2022-05-24) and has an EPSS 30-day probability of 0.876 (99.7th percentile), indicating active exploitation is expected. Multiple references are tagged Exploit, including public exploit code and a technical reverse-engineering writeup.
What to do
- Upgrade ASA/PIX/FWSM software to a fixed release per the Cisco advisory cisco-sa-20160817-asa-snmp; this is the only complete fix.
- If patching cannot be done immediately, disable SNMP on the affected devices or restrict SNMP access to trusted management hosts only.
- Replace SNMPv1/v2c with SNMPv3 and strong credentials where SNMP must remain enabled.
- Segment and firewall management interfaces so SNMP is not reachable from untrusted networks.
- Monitor Cisco advisories and CISA KEV for updated guidance and verify the fixed version is actually running after upgrade.
Detection
- Alert on SNMP traffic to ASA/PIX/FWSM management addresses from hosts outside the approved management subnet.
- Inspect device logs and SNMP service logs for malformed or oversized SNMP requests and unexpected process crashes or reloads.
- Hunt for unexpected configuration changes, new local accounts, or anomalous outbound connections originating from the firewall appliance.
- Correlate ASA syslog events with known EXTRABACON exploitation indicators and review for repeated failed SNMP authentication attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-6366 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6366 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6366), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.