← Back to CVE List
Vulnerability Intelligence Report
Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

CVE-2016-6367

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:22.58%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-77 ↗CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
cisco adaptive_security_appliance_software all
cisco asa_5500 all
cisco asa_5500-x all
cisco asa_5500_csc-ssm all
cisco asa_5505 all
cisco asa_5506-x all
cisco asa_5506h-x all
cisco asa_5506w-x all
cisco asa_5508-x all
cisco asa_5510 all
cisco asa_5512-x all
cisco asa_5515-x all
cisco asa_5516-x all
cisco asa_5520 all
cisco asa_5525-x all
cisco asa_5540 all
cisco asa_5545-x all
cisco asa_5550 all
cisco asa_5555-x all
cisco asa_5580 all
cisco asa_5585-x all
cisco firewall_services_module all
cisco pix_firewall_501 all
cisco pix_firewall_506 all
cisco pix_firewall_506e all
cisco pix_firewall_515 all
cisco pix_firewall_515e all
cisco pix_firewall_520 all
cisco pix_firewall_525 all
cisco pix_firewall_535 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
22.583%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCisco Systems, Inc. · Hosted Service · USA
Reserved2016-07-26T00:00:00
Published2016-08-18T18:00:00
Patch Date2016-08-17
Last Updated2026-01-12T20:49:46

LINK COPIED TO CLIPBOARD