Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 10 of 17
CVE-2021-1476P3MEDIUMCVSS 6.7≥ 9.13, < 9.13.1.21≥ 9.14, < 9.14.2.13+1 more2021-04-29
CVE-2021-1476 [MEDIUM] CWE-78 CVE-2021-1476: A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower T
A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient input validation of commands that are supplied
nvd
CVE-2013-3415P3HIGHCVSS 7.8v8.4v8.4\(1\)+6 more2013-10-13
CVE-2013-3415 [HIGH] CWE-119 CVE-2013-3415: Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does
Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does not properly manage memory upon an AnyConnect SSL VPN client disconnection, which allows remote attackers to cause a denial of service (memory consumption, and forwarding outage or system hang) via packets to the disconnected machine's IP address, aka Bug
nvd
CVE-2012-5419P3HIGHCVSS 7.8v8.7.1v8.7.1.12013-01-17
CVE-2012-5419 [HIGH] CWE-399 CVE-2012-5419: Cisco Adaptive Security Appliance (ASA) software 8.7.1 and 8.7.1.1 for the Cisco ASA 1000V Cloud Fir
Cisco Adaptive Security Appliance (ASA) software 8.7.1 and 8.7.1.1 for the Cisco ASA 1000V Cloud Firewall allows remote attackers to cause a denial of service (device reload) via a malformed H.225 H.323 IPv4 packet, aka Bug IDs CSCuc42812 and CSCuc88741.
nvd
CVE-2026-20013P3MEDIUMCVSS 5.8≥ 9.18.1, < 9.18.4.66≥ 9.19.1, < 9.20.3.20+2 more2026-03-04
CVE-2026-20013 [MEDIUM] CWE-401 CVE-2026-20013: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network.
This vulnerability is due to memory exhaustion caused by not fre
nvd
CVE-2026-20015P3MEDIUMCVSS 5.8≥ 9.18.1, < 9.18.4.71≥ 9.19.1, < 9.20.4.10+2 more2026-03-04
CVE-2026-20015 [MEDIUM] CWE-401 CVE-2026-20015: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network.
This vulnerability is due to a memory leak when parsing IKEv2 packets
nvd
CVE-2019-12676P3HIGHCVSS 7.4≥ 9.7, < 9.8.4.8≥ 9.9, < 9.9.2.59+2 more2019-10-02
CVE-2019-12676 [HIGH] CWE-20 CVE-2019-12676: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App
A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the affe
nvd
CVE-2019-1693P3MEDIUMCVSS 6.5fixed in 9.4.4.34≥ 9.5, < 9.6.4.25+3 more2019-05-03
CVE-2019-1693 [MEDIUM] CWE-399 CVE-2019-1693: A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco
A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper management of authenticated sessions in the WebVPN portal. An a
nvd
CVE-2022-20924P3MEDIUMCVSS 6.5v9.14.1v9.14.1.6+39 more2022-11-15
CVE-2022-20924 [MEDIUM] CWE-703 CVE-2022-20924: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation. An
nvd
CVE-2024-20485P3MEDIUMCVSS 6.7v9.8.1v9.8.1.5+192 more2024-10-23
CVE-2024-20485 [MEDIUM] CWE-94 CVE-2024-20485: A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco
A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability.
This vulnerability is due to improper v
nvd
CVE-2008-2055P4HIGHCVSS 7.8v7.1v7.2.2+1 more2008-06-04
CVE-2008-2055 [HIGH] CWE-20 CVE-2008-2055: Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.1.x before 7.1(2)70, 7.2.
Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.1.x before 7.1(2)70, 7.2.x before 7.2(4), and 8.0.x before 8.0(3)10 allows remote attackers to cause a denial of service via a crafted TCP ACK packet to the device interface.
nvd
CVE-2008-2058P4HIGHCVSS 7.8v7.2.2v8.02008-06-04
CVE-2008-2058 [HIGH] CWE-399 CVE-2008-2058: Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(3)2 and 8.
Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(3)2 and 8.0.x before 8.0(2)17 allows remote attackers to cause a denial of service (device reload) via a port scan against TCP port 443 on the device.
nvd
CVE-2026-20008P3MEDIUMCVSS 6.0≥ 9.12.1, < 9.16.4.85≥ 9.17.1, < 9.18.4.66+3 more2026-03-04
CVE-2026-20008 [MEDIUM] CWE-78 CVE-2026-20008: A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Se
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root.
This vulnerability exists because use
nvd
CVE-2023-20256P3MEDIUMCVSS 5.8v9.8.4.22v9.8.4.25+107 more2023-11-01
CVE-2023-20256 [MEDIUM] CWE-290 CVE-2023-20256: Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA)
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. These vulnerabilit
nvd
CVE-2024-20299P3MEDIUMCVSS 5.8v9.8.1v9.8.1.5+150 more2024-10-23
CVE-2024-20299 [MEDIUM] CWE-290 CVE-2024-20299: A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due
nvd
CVE-2024-20297P3MEDIUMCVSS 5.8v9.8.1v9.8.1.5+177 more2024-10-23
CVE-2024-20297 [MEDIUM] CWE-290 CVE-2024-20297: A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due
nvd
CVE-2010-4679P4HIGHCVSS 7.8≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2010-4679 [HIGH] CWE-20 CVE-2010-4679: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not prop
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly handle Online Certificate Status Protocol (OCSP) connection failures, which allows remote OCSP responders to cause a denial of service (TCP socket exhaustion) by rejecting connection attempts, aka Bug ID CSCsz36816.
nvd
CVE-2012-4659P4HIGHCVSS 7.1v8.2v8.2\(1\)+9 more2012-10-29
CVE-2012-4659 [HIGH] CWE-287 CVE-2012-4659: The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA
The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.30) and 8.3 before 8.3(2.34) allows remote attackers to cause a denial of service (device reload) via a crafted authentication
nvd
CVE-2012-0353P3HIGHCVSS 7.1v8.0v8.0\(2\)+28 more2012-03-15
CVE-2012-0353 [HIGH] CWE-20 CVE-2012-0353: The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the A
The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.5), 8.3 before 8.3(2.22), 8.4 before 8.4(2.1), and 8.5 before 8.5(1.2) does not properly handle flows, which allows
nvd
CVE-2012-4643P4HIGHCVSS 7.1v7.0v7.0\(0\)+57 more2012-10-29
CVE-2012-4643 [HIGH] CWE-399 CVE-2012-4643: The DHCP server on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Service
The DHCP server on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 before 7.2(5.8), 7.1 before 7.2(5.8), 7.2 before 7.2(5.8), 8.0 before 8.0(5.28), 8.1 before 8.1(2.56), 8.2 before 8.2(5.27), 8.3 before 8.3(2.31), 8.4 before 8.4(3.10), 8.5 before 8
nvd
CVE-2020-3334P4HIGHCVSS 7.4≥ 9.10, < 9.10.1.37≥ 9.12, < 9.12.3+1 more2020-05-06
CVE-2020-3334 [HIGH] CWE-399 CVE-2020-3334: A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition on an affected dev
nvd