Cisco Adaptive Security Appliance Software vulnerabilities
315 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
315
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
11
Severity breakdown
CRITICAL15HIGH179MEDIUM120LOW1
Vulnerabilities
Page 10 of 16
CVE-2016-1295MEDIUMCVSS 5.3v8.4.0v8.4.1+24 more2016-01-16
CVE-2016-1295 [MEDIUM] CWE-200 CVE-2016-1295: Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive inf
Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.
nvd
CVE-2015-6423MEDIUMCVSS 4.3v9.4.1v9.4.1.1+5 more2016-01-15
CVE-2015-6423 [MEDIUM] CWE-264 CVE-2015-6423: The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 throu
The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remote authenticated users to bypass an intended DCERPC-only ACL by sending arbitrary network traffic, aka Bug ID CSCuu67782.
nvd
CVE-2015-6379MEDIUMCVSS 6.8v8.4.02015-11-25
CVE-2015-6379 [MEDIUM] CWE-399 CVE-2015-6379: The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 a
The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.
nvd
CVE-2015-6326HIGHCVSS 7.8v7.2.1v7.2.1.9+179 more2015-10-25
CVE-2015-6326 [HIGH] CWE-399 CVE-2015-6326: Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.
Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.6), 9.2 before 9.2(4), 9.3 before 9.3(3.5), and 9.4 before 9.4(1.5) allows remote attackers to cause a denial of service (device reload) via a crafted DNS response, aka Bug
nvd
CVE-2015-6327HIGHCVSS 7.8v7.2.1v7.2.1.9+172 more2015-10-25
CVE-2015-6327 [HIGH] CWE-399 CVE-2015-6327: The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(
The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.8), 9.2 before 9.2(4), and 9.3 before 9.3(3) allows remote attackers to cause a denial of service (device reload) via crafted ISAKMP UDP packets,
nvd
CVE-2015-6325HIGHCVSS 7.1v7.2.1v7.2.1.9+173 more2015-10-25
CVE-2015-6325 [HIGH] CWE-399 CVE-2015-6325: Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.
Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.4), 9.2 before 9.2(4), 9.3 before 9.3(3.1), and 9.4 before 9.4(1.1) allows remote attackers to cause a denial of service (device reload) via a crafted DNS response, aka Bug
nvd
CVE-2015-6324HIGHCVSS 7.1v9.0.1v9.0.2+47 more2015-10-25
CVE-2015-6324 [HIGH] CWE-399 CVE-2015-6324: The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) software 9.0 before 9.0(4
The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) software 9.0 before 9.0(4.37), 9.1 before 9.1(6.6), 9.2 before 9.2(4), 9.3 before 9.3(3.5), and 9.4 before 9.4(2) allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug IDs CSCus56252 and CSCus57142.
nvd
CVE-2015-4321MEDIUMCVSS 5.0v9.3\(1.50\)v9.3\(2.100\)+2 more2015-08-20
CVE-2015-4321 [MEDIUM] CWE-20 CVE-2015-4321: The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA)
The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(1.50), 9.3(2.100), 9.3(3), and 9.4(1) mishandles cases where an IP address belongs to an internal interface but is also in the ASA routing table, which allows remote attackers to bypass uRPF validation via spoofed packets, aka Bug ID CSCuv6
nvd
CVE-2015-4458MEDIUMCVSS 4.3v9.1.5.212015-07-18
CVE-2015-4458 [MEDIUM] CWE-310 CVE-2015-4458: The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adapti
The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976.
nvd
CVE-2015-4241MEDIUMCVSS 6.1v9.3\(2\)2015-07-08
CVE-2015-4241 [MEDIUM] CVE-2015-4241: Cisco Adaptive Security Appliance (ASA) Software 9.3(2) allows remote attackers to cause a denial of
Cisco Adaptive Security Appliance (ASA) Software 9.3(2) allows remote attackers to cause a denial of service (system reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCut52679.
nvd
CVE-2015-4239MEDIUMCVSS 6.1v100.13\(0.21\)v9.3\(2.243\)2015-07-03
CVE-2015-4239 [MEDIUM] CWE-399 CVE-2015-4239: Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers
Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.
nvd
CVE-2015-4238MEDIUMCVSS 6.8v8.4\(7\)v8.6\(1.2\)2015-07-02
CVE-2015-4238 [MEDIUM] CWE-399 CVE-2015-4238: The SNMP implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4(7) and 8.6(1.2) allo
The SNMP implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4(7) and 8.6(1.2) allows remote authenticated users to cause a denial of service (device reload) by sending many SNMP requests during a time of high network traffic, aka Bug ID CSCul02601.
nvd
CVE-2015-4550MEDIUMCVSS 4.3v9.3\(3\)v9.4\(1.1\)2015-06-17
CVE-2015-4550 [MEDIUM] CWE-310 CVE-2015-4550: The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with sof
The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.
nvd
CVE-2015-0760MEDIUMCVSS 4.0≥ 7.0, < 8.2.2.132015-06-04
CVE-2015-0760 [MEDIUM] CWE-20 CVE-2015-0760: The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows r
The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259.
nvd
CVE-2015-0742MEDIUMCVSS 5.0v9.2\(3.4\)v9.4\(0.115\)+9 more2015-05-21
CVE-2015-0742 [MEDIUM] CWE-399 CVE-2015-0742: The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Soft
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registration, which allows remote attackers to cause a denial o
nvd
CVE-2015-0677HIGHCVSS 7.8v8.4.1v8.4.1.3+68 more2015-04-13
CVE-2015-0677 [HIGH] CWE-20 CVE-2015-0677: The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before
The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6), 9.2 before 9.2(3.4), and 9.3 before 9.3(3), when Clientless SSL VPN, AnyConnect SSL VPN, or AnyConnect IKEv2 VPN is used, allows remote attackers to cause a denial of service (VPN outage or device reload)
nvd
CVE-2015-0675HIGHCVSS 8.3v9.1.1v9.1.1.4+21 more2015-04-13
CVE-2015-0675 [HIGH] CWE-284 CVE-2015-0675: The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1
The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate failover communication messages, which allows remote attackers to reconfigure an ASA device, and consequently obtain administrative control, by sending crafted UDP packets over the
nvd
CVE-2015-0676HIGHCVSS 7.1v7.0.1v7.0.1.4+239 more2015-04-13
CVE-2015-0676 [HIGH] CWE-20 CVE-2015-0676: The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2
The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 before 9.1(6.1), 9.2 before 9.2(3.4), and 9.3 before 9.3(3) allows man-in-the-middle attackers to cau
nvd
CVE-2014-8023MEDIUMCVSS 4.0≤ 9.2.32015-02-17
CVE-2014-8023 [MEDIUM] CWE-264 CVE-2014-8023: Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authen
Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, does not properly select tunnel groups, which allows remote authenticated users to bypass intended resource-access restrictions via a crafted tunnel-group parameter, aka Bug ID CSCtz48533.
nvd
CVE-2013-5557MEDIUMCVSS 6.3≤ 9.1\(2\)2015-02-07
CVE-2013-5557 [MEDIUM] CVE-2013-5557: The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Applian
The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP request that triggers a rewrite, aka Bug ID CSCug91577.
nvd