CVE-2016-6366

HIGH KEV

Cisco ASA Authentication Bypass (EXTRABACON)

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2016-6366 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 24, 2022. EIP tracks 3 public exploits from researchers including Shadow Brokers, RiskSense-Ops, Sean Dillon <[email protected]>, Zachary Harding <[email protected]>, Nate Caroe <[email protected]>, Dylan Davis <[email protected]>, including a Metasploit module auxiliary/admin/networking/cisco_asa_extrabacon.

AI-analyzed exploit summary This is a writeup describing an authentication bypass vulnerability in Cisco ASA 8.X. It outlines requirements and provides a link to the full exploit but does not contain actual exploit code.

Description

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

Exploits (3)

exploitdb WRITEUP
by Shadow Brokers · textremotehardware
https://www.exploit-db.com/exploits/40258

This is a writeup describing an authentication bypass vulnerability in Cisco ASA 8.X. It outlines requirements and provides a link to the full exploit but does not contain actual exploit code.

Classification
Writeup 80%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Cisco ASA 8.X
No auth needed
Prerequisites: SNMP read access · Access to SNMP service · SSH port accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 163 stars
by RiskSense-Ops · remote-auth
https://github.com/RiskSense-Ops/CVE-2016-6366

This repository contains an improved version of the EXTRABACON exploit for CVE-2016-6366, a remote code execution vulnerability in Cisco ASA devices. It includes functional exploit code, shellcode for multiple versions, and a LINA offset finder script to extend support to additional versions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Cisco ASA (8.x and 9.x versions)
No auth needed
Prerequisites: Network access to vulnerable Cisco ASA device · SNMP service enabled on target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC
by Sean Dillon <[email protected]>, Zachary Harding <[email protected]>, Nate Caroe <[email protected]>, Dylan Davis <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/networking/cisco_asa_extrabacon.rb

This Metasploit module exploits CVE-2016-6366, an authentication bypass vulnerability in Cisco ASA devices via SNMP. It patches authentication functions to allow uncredentialed logins by leveraging version-specific offsets for shellcode execution.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Cisco ASA (multiple versions from 8.0(2) to 9.2(4)13)
No auth needed
Prerequisites: SNMP access to target device · Knowledge of target ASA version (or autodetection)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Broken Link, Not Applicable, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92521
Exploit, Press/Media Coverage, Vendor Advisory x_refsource_confirm
http://blogs.cisco.com/security/shadow-brokers
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40258/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036637

Scores

CVSS v3 8.8
EPSS 0.9078
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-05-24
VulnCheck KEV 2016-08-15
InTheWild.io 2016-08-15
ENISA EUVD EUVD-2016-7289
CWE
CWE-120
Status published
Products (4)
cisco/adaptive_security_appliance_software 7.2.1 - 9.0.4.40
cisco/asa_1000v_cloud_firewall_software 8.7.1
cisco/asa_1000v_cloud_firewall_software 8.7.1.1
cisco/pix_firewall_software
Published Aug 18, 2016
KEV Added May 24, 2022
Tracked Since Feb 18, 2026