HIGH · 8.8

CVE-2016-6366

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM dev...

Vulnerability Description

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoPix Firewall Software-
CiscoPix Firewall 501-
CiscoPix Firewall 506-
CiscoPix Firewall 506E-
CiscoPix Firewall 515-
CiscoPix Firewall 515E-
CiscoPix Firewall 520-
CiscoPix Firewall 525-
CiscoPix Firewall 535-
CiscoAdaptive Security Appliance Software>= 7.2.1, < 9.0.4.40
Cisco7604-
Cisco7606-S-
Cisco7609-S-
Cisco7613-S-
CiscoAsa 5500-
CiscoAsa 5500-X-
CiscoAsa 5500 Csc-Ssm-
CiscoAsa 5505-
CiscoAsa 5506-X-
CiscoAsa 5506H-X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-6366?

CVE-2016-6366 is a vulnerability with a CVSS score of 8.8 (HIGH). Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM dev...

How severe is CVE-2016-6366?

CVE-2016-6366 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-6366?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Pix Firewall Software, Cisco Pix Firewall 501, Cisco Pix Firewall 506, Cisco Pix Firewall 506E, Cisco Pix Firewall 515.