A vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3) when enabled on a virtual or physical Cisco ASA device. An attacker could exploit this vulnerability by sending crafted SNMP packets to an SNMP-enabled interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. The attacker must know the SNMP community string to exploit this vulnerability. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed and transparent firewall mode only and in single or multiple context mode. This vulnerability can be triggered by IPv4 traffic only. The attacker requires knowledge of the configured SNMP community string in SNMP version 1 and SNMP version 2c or a valid username and password for SNMP version 3. Cisco has released software updates that address this vulnerability. Mitigations are listed in the Workarounds section of this advisory. This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-snmp
Cisco ASA Major Release | First Fixed Release |
7.2 | Affected; migrate to 9.1.7(9) or later |
8.0 | Affected; migrate to 9.1.7(9) or later |
8.1 | Affected; migrate to 9.1.7(9) or later |
8.2 | Affected; migrate to 9.1.7(9) or later |
8.3 | Affected; migrate to 9.1.7(9) or later |
8.4 | Affected; migrate to 9.1.7(9) or later |
8.5 | Affected; migrate to 9.1.7(9) or later |
8.6 | Affected; migrate to 9.1.7(9) or later |
8.7 | Affected; migrate to 9.1.7(9) or later |
9.0 | 9.0.4(40) |
9.1 | 9.1.7(9) |
9.2 | 9.2.4(14) |
9.3 | 9.3.3(10) |
9.4 | 9.4.3(8) ETA 8/26/2016 |
9.5 | 9.5(3) ETA 8/30/2016 |
9.6 (FTD) | 9.6.1(11) / FTD 6.0.1(2) |
9.6 (ASA) | 9.6.2 |
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.
Version | Description | Section | Status | Date |
---|---|---|---|---|
1.5 | Updated Affected Products to add an affected release of ASA software. | Affected Products | Interim | 2016-September-19 |
1.4 | Updated Summary text for additional clarification, updated Fixed Software section to reflect recently published software versions. | Summary, Fixed Software | Interim | 2016-August-25 |
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. CISCO EXPECTS TO UPDATE THIS DOCUMENT AS NEW INFORMATION BECOMES AVAILABLE.
A standalone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy and may lack important information or contain factual errors. The information in this document is intended for end users of Cisco products.