{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:13:32Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"cisco-sa-20160928-aos","slug":"cisco-sa-20160928-aos","vendor":"Cisco","title":"Cisco AsyncOS File Transfer Protocol Denial of Service Vulnerability","summary":"A vulnerability in the local File Transfer Protocol (FTP) service on the Cisco AsyncOS for Email Security Appliance (ESA), Web Security Appliance (WSA), and Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to lack of throttling of FTP connections. An attacker could exploit this vulnerability by sending a flood of FTP traffic to the local FTP service on the targeted device. An exploit could allow the attacker to cause a DoS condition. CONDITION(s): The local FTP service is enabled. This is not the default configuration. To check if local FTP service is enabled, the administrator can use either the GUI or command-line interface (CLI). 1. On the GUI, navigate to Network -&gt; IP Interfaces, click the name of the interface, and in the Services section, check if the FTP service is enabled. 2. For the CLI, the parameter “Do you want to enable FTP on this interface?” would be set to Yes. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-aos","severity":"Medium","published_at":"2016-09-28T16:00:00Z","updated_at":"2016-09-28T16:00:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-aos","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/cisco-sa-20160928-aos/csaf/cisco-sa-20160928-aos.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":3,"public_evidence_count":3,"kev_count":0,"highest_epss":0.0202},"cves":[{"id":"CVE-2016-6416","kev":false,"epss":{"score":0.0202,"percentile":0.78804,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"}}],"public_evidence":[{"product":{"name":"Cisco Email Security Appliance (ESA)","slug":"cisco-email-security-appliance-esa","vendor":"Cisco"},"cve":{"id":"CVE-2016-6416"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:38:21Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Email Security Appliance (ESA)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.0202,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2016-09-28T16:00:00Z","updated_at":"2016-09-28T16:00:00Z","advisory_updated_at":"2016-09-28T16:00:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-aos","row_display_order":1},{"product":{"name":"Cisco Content Security Management Appliance (SMA)","slug":"cisco-content-security-management-appliance-sma","vendor":"Cisco"},"cve":{"id":"CVE-2016-6416"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:38:21Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Content Security Management Appliance (SMA)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.0202,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2016-09-28T16:00:00Z","updated_at":"2016-09-28T16:00:00Z","advisory_updated_at":"2016-09-28T16:00:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-aos","row_display_order":2},{"product":{"name":"Cisco Web Security Appliance (WSA)","slug":"cisco-web-security-appliance-wsa","vendor":"Cisco"},"cve":{"id":"CVE-2016-6416"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:38:21Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Web Security Appliance (WSA)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.0202,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2016-09-28T16:00:00Z","updated_at":"2016-09-28T16:00:00Z","advisory_updated_at":"2016-09-28T16:00:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-aos","row_display_order":3}]}