CVE-2016-6367
cisco adaptive security appliance software
Published 18 Aug 2016 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 24 May 2022, with a remediation deadline of 14 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
References
- blogs.cisco.com/security/shadow-brokers · Exploit, Press/Media Coverage, Vendor Advisory
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-cli · Vendor Advisory
- tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516 · Vendor Advisory
- www.securityfocus.com/bid/92520 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1036636 · Broken Link, Third Party Advisory, VDB Entry
- github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40271.zip · Broken Link, Exploit
- www.exploit-db.com/exploits/40271/ · Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6367 · US Government Resource