← Vulnerability feed

Vulnerability record · CVE-2016-6367 · published 18 August 2016

CVE-2016-6367: Cisco ASA CLI command injection privilege escalation

Cisco · Adaptive Security Appliance Software

Cisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77). A local user with CLI access can escalate privileges on the affected appliance.

7.8 CVSS 3.1 High CISA KEV since 24 May 2022 EPSS 23% · top 2.4% CWE-77 · Command injection
7.8CVSS 3.1 base score, v2 6.8
23%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
15References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.8, confirmed exploitation in CISA KEV, and public exploit code make this a high-priority local privilege escalation for unpatched ASA deployments.

What it is

Cisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77). A local user with CLI access can escalate privileges on the affected appliance.

Impact

An attacker with local CLI access gains elevated privileges on the ASA, potentially achieving full control of the device's confidentiality, integrity, and availability (CVSS 3.1 base 7.8).

Attack surface

Reached through the local CLI by supplying crafted invalid commands; the CVSS vector (AV:L/PR:L/UI:N) indicates local access and low privileges are required, with no user interaction.

Exploitation

CISA KEV lists it as exploited (added 2022-05-24), and EPSS 30-day probability is 0.22583 (97.6th percentile); references include Exploit and ExploitDB tags, indicating public exploit code exists.

What to do

  • Upgrade Cisco ASA Software to 8.4(1) or later per the Cisco advisory cisco-sa-20160817-asa-cli.
  • Restrict and monitor local CLI access to ASA, PIX, and FWSM devices to trusted administrators only.
  • Apply the vendor's required action from the CISA KEV entry and verify version compliance across all affected appliances.
  • Where immediate upgrade is not possible, limit interactive CLI sessions and enforce least-privilege accounts.

Detection

  • Monitor ASA CLI logs for sequences of invalid or malformed commands preceding privilege changes.
  • Alert on unexpected privilege escalation or configuration changes from low-privileged CLI accounts.
  • Hunt for known exploit artifacts or command patterns associated with EPICBANANA/CSCtu74257 in device logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-6367 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-6367 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.5CVE-2020-3452Cisco ASA and FTD web services path traversal file readCisco ASA and FTD web services fail to validate URL input, allowing directory traversal sequences in HTTP requests to read files inside the web servi…KEVEPSS 100%analysed7.5CVE-2020-3259Cisco ASA and FTD web services memory disclosure via crafted URLCisco ASA and FTD web services interfaces mishandle buffer tracking when parsing invalid URLs, allowing memory contents to be read. The flaw affects …KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2016-6367), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.