CVE-2016-6366 is a critical buffer overflow vulnerability in Cisco Adaptive Security Appliance (ASA) Software, affecting various ASA devices, PIX, and FWSM. It allows remote authenticated attackers to execute arbitrary code via crafted IPv4 SNMP packets. With a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 100/100, this vulnerability presents a significant threat due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. Notably, this flaw, also known as EXTRABACON, is actively exploited in the wild and has publicly available exploit code, including Metasploit modules and ExploitDB entries. The vulnerability has garnered substantial community discussion and media coverage, highlighting its widespread recognition and the urgency of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:pix_firewall_software:-:*:*:*:*:*:*:* | ||
>= 7.2.1, < 9.0.4.40CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.1.1, < 9.1.7\(9\)CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.2.0, < 9.2.4\(14\)CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.3.0, < 9.3.3\(10\)CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.