CVE-2016-6366, also known as EXTRABACON, is a buffer overflow vulnerability in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3, affecting multiple ASA models including ASA 5500, 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM. The vulnerability resides in the SNMP implementation and allows remote authenticated users to execute arbitrary code by sending crafted IPv4 SNMP packets. The vulnerable code is in the main 'lina' binary, which lacks modern exploit mitigations in older firmware versions, making exploitation feasible.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module implementing the EXTRABACON exploit (CVE-2016-6366) targeting Cisco ASA devices. The module exploits a vulnerability in the SNMP service of specific ASA firmware versions, allowing an attacker to bypass authentication by sending a specially crafted SNMP payload. The exploit works by patching authentication routines in memory, effectively disabling password checks and enabling uncredentialed logins. The module supports multiple ASA versions, each with specific offsets for the exploit payload. The main attack vector is network-based, requiring SNMP v2c access to the target device. The code includes logic to fingerprint the ASA version using SNMP OIDs and constructs the payload accordingly. The repository is operational in maturity, providing a working exploit with version-specific payloads, but payload customization is limited to the provided actions (enabling/disabling password authentication).
This repository contains an operational exploit for CVE-2016-6366 (EXTRABACON), a remote code execution vulnerability in Cisco ASA firewalls. The exploit targets the SNMP service (UDP port 161) on vulnerable ASA versions, using a crafted SNMP packet to trigger a buffer overflow and execute custom shellcode. The repository includes: - The main exploit logic in `extrabacon-2.0/extrabacon_2.0.py`, which handles payload generation, version detection, and exploit delivery. - A set of version-specific shellcode files in `extrabacon-2.0/improved/`, supporting a wide range of ASA firmware versions (8.x and 9.x). - Utility scripts for extracting offsets from firmware and generating new shellcode modules. - An embedded copy of the Scapy library for packet crafting. The exploit allows an attacker to disable or enable password checking or execute arbitrary code on the target ASA. The attack vector is network-based, requiring access to the SNMP service. The exploit is mature and operational, with support for many ASA versions and the ability to extend to new versions by generating new shellcode modules. No hardcoded IPs or credentials are present; the exploit is configurable for different targets and payloads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.