cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.

Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1

Vulnerabilities

Page 1 of 17
CVE-2016-6366P1HIGHCVSS 8.8KEVPoC≥ 7.2.1, < 9.0.4.40≥ 9.1.1, < 9.1.7\(9\)+5 more2016-08-18
CVE-2016-6366 [HIGH] CWE-120 CVE-2016-6366: Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.
nvd
CVE-2025-20362P1HIGHCVSS 8.6KEVPoC≥ 9.12, < 9.12.4.72≥ 9.14, < 9.14.4.28+5 more2025-09-25
CVE-2025-20362 [HIGH] CVE-2025-20362: Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisc Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all
nvd
CVE-2020-3452P1HIGHCVSS 7.5KEVPoC≥ 9.6, < 9.6.4.42≥ 9.8, < 9.8.4.20+5 more2020-07-22
CVE-2020-3452 [HIGH] CWE-20 CVE-2020-3452: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in H
nvd
CVE-2018-0296P1HIGHCVSS 7.5KEVPoC≥ 9.1, < 9.1.7.29≥ 9.2, < 9.2.4.33+5 more2018-06-07
CVE-2018-0296 [HIGH] CWE-20 CVE-2018-0296: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an u A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system
nvd
CVE-2020-3580P1MEDIUMCVSS 6.1KEVPoCRansomwarefixed in 9.8.4.34≥ 9.9, < 9.9.2.85+4 more2020-10-21
CVE-2020-3580 [MEDIUM] CWE-79 CVE-2020-3580: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2016-6367P1HIGHCVSS 7.8KEVPoC≥ 7.2.0, < 8.4\(3\)≥ 8.5, < 9.0\(1\)2016-08-18
CVE-2016-6367 [HIGH] CWE-77 CVE-2016-6367: Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWS Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
nvd
CVE-2025-20333P1CRITICALCVSS 9.9KEV≥ 9.12, < 9.12.4.72≥ 9.14, < 9.14.4.28+6 more2025-09-25
CVE-2025-20333 [CRITICAL] CWE-120 CVE-2025-20333: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Sof A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests.
nvd
CVE-2020-3259P1HIGHCVSS 7.5KEVRansomware≥ 9.8, < 9.8.4.20≥ 9.9, < 9.9.2.67+3 more2020-05-06
CVE-2020-3259 [HIGH] CWE-200 CVE-2020-3259: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer trackin
nvd
CVE-2023-20269P1CRITICALCVSS 9.1KEVRansomwarev9.8.1v9.8.1.5+168 more2023-09-06
CVE-2023-20269 [CRITICAL] CWE-288 CVE-2023-20269: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a
nvd
CVE-2024-20353P1HIGHCVSS 8.6KEVRansomwarev9.8.1v9.8.1.5+185 more2024-04-24
CVE-2024-20353 [HIGH] CWE-835 CVE-2024-20353: A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) So A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking
nvd
CVE-2024-20359P1MEDIUMCVSS 6.0KEVRansomwarev9.8.1v9.8.1.5+185 more2024-04-24
CVE-2024-20359 [MEDIUM] CWE-94 CVE-2024-20359: A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins a A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level priv
nvd
CVE-2024-20481P2MEDIUMCVSS 5.8KEVv9.8.1v9.8.1.5+197 more2024-10-23
CVE-2024-20481 [MEDIUM] CWE-772 CVE-2024-20481: A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnera
nvd
CVE-2018-0101P1CRITICALCVSS 10.0ExploitedPoCfixed in 9.1.7.23≥ 9.2.0, < 9.2.4.27+5 more2018-01-29
CVE-2018-0101 [CRITICAL] CWE-415 CVE-2018-0101: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security A A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled o
nvd
CVE-2020-3187P1CRITICALCVSS 9.1ExploitedPoC≥ 9.6, < 9.6.4.40≥ 9.8, < 9.8.4.15+4 more2020-05-06
CVE-2020-3187 [CRITICAL] CWE-22 CVE-2020-3187: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of prop
nvd
CVE-2025-20363P1CRITICALCVSS 9.0Exploited≥ 9.12, < 9.12.4.72≥ 9.14, < 9.14.4.28+6 more2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS,
nvd
CVE-2016-1287P1CRITICALCVSS 9.8PoCv7.2.1v7.2.1.9+197 more2016-02-11
CVE-2016-1287 [CRITICAL] CWE-119 CVE-2016-1287: Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 b Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 devices, ASA 5500-X devices, ASA Services Module for Cisco Catalyst 6500 and Cisco 7600 device
nvd
CVE-2020-3529P2HIGHCVSS 7.5Exploited≥ 9.8.0, < 9.8.4.29≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3529 [HIGH] CWE-400 CVE-2020-3529: A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Softw A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to inefficient direct memory access (
nvd
CVE-2018-15454P2HIGHCVSS 8.6Exploited≥ 9.4, < 9.4.4.27≥ 9.6, < 9.6.4.18+3 more2018-11-01
CVE-2018-15454 [HIGH] CWE-20 CVE-2018-15454: A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Securit A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is
nvd
CVE-2014-3393P2MEDIUMCVSS 4.3Exploitedv8.2v8.2.0.45+100 more2014-10-10
CVE-2014-3393 [MEDIUM] CWE-287 CVE-2014-3393: The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8. The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement authentication, which allows remote attackers to modify RAMFS customization objects via unspe
nvd
CVE-2017-3807P2HIGHCVSS 8.8PoCv7.0.1v7.0.1.4+322 more2017-02-09
CVE-2017-3807 [HIGH] CWE-119 CVE-2017-3807: A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by sending a craf
nvd
1 / 17Next →