EXPOSURES › CVE-2016-6366
CVE-2016-6366
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco ASA's SNMP code had a buffer overflow allowing remote code execution or system reloads.
A buffer overflow in Cisco ASA's SNMP code let attackers remotely execute code or reload the system, posing a severe risk to network security. DIB organizations must ensure all Cisco ASA devices are patched against CVE-2016-6366 to prevent exploitation, especially since it was actively exploited in the wild. This failure highlights the critical need for timely patching of known vulnerabilities in network infrastructure.
Shame score — A known buffer overflow in critical network infrastructure was actively exploited in the wild, demonstrating severe negligence in patching and vulnerability management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |