CVE-2016-6367: Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-05-24. EPSS: 22.6% chance of exploitation in the next 30 days.

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

Affected products

  • Cisco Adaptive Security Appliance Software: from 7.2.0, before 8.4\(3\) (fixed in 8.4\(3\)); from 8.5, before 9.0\(1\) (fixed in 9.0\(1\))

Published 2016-08-18. Last modified 2026-06-17.