Skip to content
COOEY

EXPOSURES › CVE-2016-6367

CVE-2016-6367

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-6367 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatched

Cisco ASA CLI parser flaw allowed authenticated local attackers to cause DoS or execute code.

The Cisco Adaptive Security Appliance (ASA) CLI parser vulnerability allowed an authenticated local attacker to execute code or cause a denial-of-service. DIB organizations must ensure their ASA devices are patched, as this flaw was actively exploited in the wild and could compromise network security controls.

Shame score — A known vulnerability in a critical network security device was actively exploited in the wild, indicating a failure to patch a known issue in a high-value target.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized