Cisco Adaptive Security Appliance vulnerabilities
47 known vulnerabilities affecting cisco/adaptive_security_appliance.
Total CVEs
47
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
HIGH35MEDIUM12
Vulnerabilities
Page 3 of 3
CVE-2021-34790P4MEDIUMCVSS 5.3fixed in 9.8.4.402021-10-27
CVE-2021-34790 [MEDIUM] CWE-358 CVE-2021-34790: Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For mo
nvd
CVE-2019-12695P4MEDIUMCVSS 6.1fixed in 9.6.4.312019-10-02
CVE-2019-12695 [MEDIUM] CWE-79 CVE-2019-12695: A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA)
A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to in
nvd
CVE-2020-3599P4MEDIUMCVSS 6.1fixed in 9.6.4.452020-10-21
CVE-2020-3599 [MEDIUM] CWE-79 CVE-2020-3599: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Sof
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An
nvd
CVE-2007-5569P4HIGHCVSS 7.1v7.22007-10-18
CVE-2007-5569 [HIGH] CWE-20 CVE-2007-5569: Cisco PIX and ASA appliances with 7.1 and 7.2 software, when configured for TLS sessions to the devi
Cisco PIX and ASA appliances with 7.1 and 7.2 software, when configured for TLS sessions to the device, allow remote attackers to cause a denial of service (device reload) via a crafted TLS packet, aka CSCsg43276 and CSCsh97120.
nvd
CVE-2020-3561P4MEDIUMCVSS 4.7fixed in 9.6.4.352020-10-21
CVE-2020-3561 [MEDIUM] CWE-93 CVE-2020-3561: A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Softwa
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the affected system. The vulnerability is due to improper input sanitization. An attacker could expl
nvd
CVE-2019-12693P4MEDIUMCVSS 4.9fixed in 9.6.4.302019-10-02
CVE-2019-12693 [MEDIUM] CWE-704 CVE-2019-12693: A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the use of an incorrect data type for a length variable. An attacker could exploit this vulnerability by initiating the transfer o
nvd
CVE-2009-1202P4MEDIUMCVSS 4.3v8.0\(4\)v8.1.2+1 more2009-06-25
CVE-2009-1202 [MEDIUM] CWE-79 CVE-2009-1202: WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1
WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.
nvd
← Previous3 / 3