EXPOSURES › CVE-2016-6367
CVE-2016-6367
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco ASA CLI parser flaw allowed authenticated local attackers to cause DoS or execute code.
The Cisco Adaptive Security Appliance (ASA) CLI parser vulnerability allowed an authenticated local attacker to execute code or cause a denial-of-service. DIB organizations must ensure their ASA devices are patched, as this flaw was actively exploited in the wild and could compromise network security controls.
Shame score — A known vulnerability in a critical network security device was actively exploited in the wild, indicating a failure to patch a known issue in a high-value target.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |