Security Alert: Cisco ASA SNMP Remote Code Execution Vulnerability (CVE-2016-6366)


Very recently, a new security vulnerability affecting Cisco ASA & Firepower was discovered. Below are the short details:

A vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to a buffer overflow in the affected code area. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. The attacker must know the SNMP community string to exploit this vulnerability.

Affected Products:
  • Cisco ASA 5500 Series Adaptive Security Appliances
  • Cisco ASA 5500-X Series Next-Generation Firewalls
  • Cisco ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers
  • Cisco ASA 1000V Cloud Firewall
  • Cisco Adaptive Security Virtual Appliance (ASAv)
  • Cisco Firepower 4100 Series
  • Cisco Firepower 9300 ASA Security Module
  • Cisco Firepower Threat Defense Software
  • Cisco Firewall Services Module (FWSM)*
  • Cisco Industrial Security Appliance 3000 
  • Cisco PIX Firewalls

IOS Fix:

Cisco ASA Major Release First Fixed Release
 7.2Affected; migrate to 9.1.7(9) or later
 8.0Affected; migrate to 9.1.7(9) or later
8.1Affected; migrate to 9.1.7(9) or later
8.2Affected; migrate to 9.1.7(9) or later
8.3Affected; migrate to 9.1.7(9) or later
8.4Affected; migrate to 9.1.7(9) or later
8.5Affected; migrate to 9.1.7(9) or later
8.6Affected; migrate to 9.1.7(9) or later
8.7Affected; migrate to 9.1.7(9) or later ETA 8/25/2016 ETA 8/25/2016 ETA 8/26/2016 ETA 8/26/2016
9.59.5(3) / FTD 6.0.1(2)

For up-to-date details of the vulnerability, kindly check the following link:

For more information or assistance in patching the above vulnerability, don't hesitate to contact us through our call center on +961-1-511822.

Elie Bassil
Next Post »


Write comments
December 4, 2017 at 8:48 AM delete

I like the post format as you create user engagement in the complete article. It seems round up of all published posts. Thanks for gauging the informative posts.
cara menggugurkan kandungan
cara menggugurkan kandungan

August 17, 2018 at 5:44 AM delete

Definitely believe that which you said. Your favorite reason appeared to be on the web the easiest thing to be aware of. I say to you, I definitely get irked while people think about worries that they just do not know about. You managed to hit the nail upon the top and also defined out the whole thing without having side effect , people could take a signal. Will likely be back to get more. Thanks
Tangki Panel