Vulnerability record · CVE-2016-6367 · published 18 August 2016
CVE-2016-6367: Cisco ASA CLI command injection privilege escalation
Cisco · Adaptive Security Appliance Software
Cisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77). A local user with CLI access can escalate privileges on the affected appliance.
Description
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8, confirmed exploitation in CISA KEV, and public exploit code make this a high-priority local privilege escalation for unpatched ASA deployments.
What it is
Cisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77). A local user with CLI access can escalate privileges on the affected appliance.
Impact
An attacker with local CLI access gains elevated privileges on the ASA, potentially achieving full control of the device's confidentiality, integrity, and availability (CVSS 3.1 base 7.8).
Attack surface
Reached through the local CLI by supplying crafted invalid commands; the CVSS vector (AV:L/PR:L/UI:N) indicates local access and low privileges are required, with no user interaction.
Exploitation
CISA KEV lists it as exploited (added 2022-05-24), and EPSS 30-day probability is 0.22583 (97.6th percentile); references include Exploit and ExploitDB tags, indicating public exploit code exists.
What to do
- Upgrade Cisco ASA Software to 8.4(1) or later per the Cisco advisory cisco-sa-20160817-asa-cli.
- Restrict and monitor local CLI access to ASA, PIX, and FWSM devices to trusted administrators only.
- Apply the vendor's required action from the CISA KEV entry and verify version compliance across all affected appliances.
- Where immediate upgrade is not possible, limit interactive CLI sessions and enforce least-privilege accounts.
Detection
- Monitor ASA CLI logs for sequences of invalid or malformed commands preceding privilege changes.
- Alert on unexpected privilege escalation or configuration changes from low-privileged CLI accounts.
- Hunt for known exploit artifacts or command patterns associated with EPICBANANA/CSCtu74257 in device logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-6367 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6367 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6367), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.