No fixed build is published yet. The vendor describes a workaround.
Steps
Written by AI from the record
Check whether you are running Blue Coat Advanced Secure Gateway (ASG) 6.6 with version earlier than 6.6.5.4, or Content Analysis System (CAS) 1.3 with version earlier than 1.3.7.4.
If you are on an affected version, contact your vendor/support or your MSP to confirm whether an updated release containing a fix exists for your exact build; no fix/patch information is available in the provided data.
Restrict and audit access to any administrator accounts for these systems (remove unnecessary admin users, enforce strong passwords/lockouts, and review who can log in as an admin).
If you must keep the system running temporarily, reduce exposure by tightening network access controls so only required management and service traffic can reach these appliances from allowed networks.
Monitor for suspicious admin activity around command/automation features (unexpected changes, unusual process activity, or configuration changes) and preserve logs for incident review if anything looks off.
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges.
In plain language
Written by AI from the record
If you run Blue Coat Advanced Secure Gateway (ASG) or its Content Analysis System (CAS) in affected versions, a logged-in malicious admin could run operating-system commands on the server with high privileges; small businesses should prioritize a fix only if you have (or could be given) admin access, and a patch is not currently confirmed.
CVE-2016-9091 is an OS command injection in Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 where an authenticated malicious administrator can trigger arbitrary OS command execution with elevated privileges; public exploits exist.
If you're affected
Full server compromise
Malware or persistence risk
Service disruption
Sensitive data theft
What is it
This vulnerability lets a malicious administrator type commands that the system runs as if they were the server itself. Think of it like an “admin console” that, if misused, can execute anything on the machine—not just change settings. Because admin access is required, the biggest risk is if an attacker gets (or is already) logged in as an administrator.
Who is affected
This matters if your business uses Blue Coat Advanced Secure Gateway (ASG) or the Content Analysis System (CAS) software in affected versions. The dangerous part requires an attacker to have authenticated admin-level access, so it’s primarily a risk if someone can log in as an administrator or if admin credentials are compromised. The risk is present only when the vulnerable versions are in use and an attacker can reach the system with admin authentication (unauthorized internet reachability alone isn’t the main requirement based on the findings).
How urgent is it
Treat this as an urgent security risk within your environment because public exploits are available and the weakness allows elevated command execution. Even though it needs an authenticated malicious administrator, real-world compromise often starts with stolen or over-privileged admin access, so you should act to identify affected versions and lock down admin access now. The overall severity is reflected in a traffic-light AMBER posture: prioritize remediation, but focus on confirmed exposure and access control first.
What to do — in detail
Confirm exposure (affected version)
Locate the installed versions for:
Blue Coat Advanced Secure Gateway (ASG) 6.6 (determine if it is earlier than 6.6.5.4)
Content Analysis System (CAS) 1.3 (determine if it is earlier than 1.3.7.4)
If either component is within the affected range, assume you are exposed to the command injection behavior described.
Confirm availability of a fix
The provided findings state no fix/patch information is available. That means you cannot reliably self-select a “known-good” fixed version from this data alone.
Ask your vendor/support channel or MSP for:
The exact fixed release (if one exists) for your ASG and CAS build
Upgrade steps and any compatibility considerations for your network deployment
Reduce the most important risk factor: admin access
Because exploitation requires an authenticated malicious administrator, the practical mitigation focus is preventing attackers from obtaining that level of access.
Inventory all admin users and remove any that are not strictly necessary.
Enforce/verify strong authentication for admin accounts and lockouts/monitoring for repeated failed logins.
Review recent admin logins and changes around the time window you care about (especially after any password resets or support actions).
Temporary compensating controls (if patching is delayed)
Limit network reachability to these systems’ administrative interfaces to only required sources (e.g., specific management subnets/bastion hosts).
Block or restrict any unnecessary inbound management access.
Increase monitoring around configuration changes and unusual admin-driven behavior.
What to monitor
Unexpected or out-of-hours admin logins.
Changes to system configuration that normally require controlled procedures.
Signs of process creation/spawn behavior that doesn’t match typical operation (log sources depend on your deployment).
KEV / exploitation status note
This CVE is not listed in CISA KEV in the provided findings, but there is public exploit availability. That combination supports prioritizing remediation and access hardening now.
Due dates
No CISA due date is provided in the findings.
Technical context
Severity and weakness
Weakness type: CWE-78 (OS command injection).
Impact capability: an authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges, which can lead to full compromise, data theft, and denial of service.
Affected products and versions
advanced secure gateway (Blue Coat ASG) 6.6 before 6.6.5.4.
content analysis system software (Blue Coat CAS) 1.3 before 1.3.7.4.
Exploit maturity / public availability
The findings indicate public exploits exist (2 known), increasing the likelihood that attackers can readily weaponize this issue.
No KEV listing is provided, so this is not confirmed as a KEV-tracked vulnerability in the supplied data.
Attack vector and prerequisites
Exploitation requires authenticated malicious administrator access, aligning with the mechanism described in the findings.
Because admin authentication is required, the main real-world risk driver is compromise or misuse of admin credentials.
EPSS note
EPSS is reported as a prediction in the findings (trend: falling), but public exploitation availability is treated as more actionable than predictions.
KEV meaning here
“Not listed in CISA KEV” means it has not been included in that specific CISA catalog based on the provided data; it does not negate the presence of public exploits.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.