Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 11 of 17
CVE-2019-1944P4HIGHCVSS 7.3fixed in 9.4.4.372019-08-07
CVE-2019-1944 [HIGH] CWE-20 CVE-2019-1944: Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisor
nvd
CVE-2021-40125P4MEDIUMCVSS 6.5≥ 9.8.0, < 9.8.4.40≥ 9.9.0, < 9.12.4.30+3 more2021-10-27
CVE-2021-40125 [MEDIUM] CWE-416 CVE-2021-40125: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Secu
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. This vulnerability is due to improper control of a reso
nvd
CVE-2020-3457P4MEDIUMCVSS 6.7≥ 9.8, < 9.8.4.29≥ 9.9, < 9.9.2.80+3 more2020-10-21
CVE-2020-3457 [MEDIUM] CWE-78 CVE-2020-3457: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to in
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted
nvd
CVE-2022-20927P4MEDIUMCVSS 6.5v9.13.1v9.13.1.2+32 more2022-11-15
CVE-2022-20927 [MEDIUM] CWE-120 CVE-2022-20927: A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper memory management when a device initiates SSL/TLS connection
nvd
CVE-2007-2463P4HIGHCVSS 7.8≤ 7.2.2v7.12007-05-02
CVE-2007-2463 [HIGH] CVE-2007-2463: Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and
Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)17 allows remote attackers to cause a denial of service (device reload) via unknown vectors related to VPN connection termination and password expiry.
nvd
CVE-2008-2056P4HIGHCVSS 7.8v8.02008-06-04
CVE-2008-2056 [HIGH] CWE-20 CVE-2008-2056: Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 and 8.
Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 and 8.1.x before 8.1(1)1 allows remote attackers to cause a denial of service (device reload) via a crafted Transport Layer Security (TLS) packet to the device interface.
nvd
CVE-2024-20331P3MEDIUMCVSS 5.9v9.8.1v9.8.1.5+186 more2024-10-23
CVE-2024-20331 [MEDIUM] CWE-330 CVE-2024-20331: A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent users from authenticating.
This vulnerability is due to insufficient entropy in the authentic
nvd
CVE-2022-20928P4MEDIUMCVSS 5.8v9.6.1v9.6.1.3+216 more2022-11-15
CVE-2022-20928 [MEDIUM] CWE-863 CVE-2022-20928: A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive
A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user.
This vulnerability is due to a flaw in the authorization verifications during t
nvd
CVE-2023-20245P4MEDIUMCVSS 5.8v9.8.3.14v9.8.3.16+140 more2023-11-01
CVE-2023-20245 [MEDIUM] CWE-290 CVE-2023-20245: Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA)
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. These vulnerabilit
nvd
CVE-2024-20384P4MEDIUMCVSS 5.8v9.16.1v9.16.1.28+70 more2024-10-23
CVE-2024-20384 [MEDIUM] CWE-290 CVE-2024-20384: A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA
A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device.
This vulnerabilit
nvd
CVE-2024-20293P4MEDIUMCVSS 5.8≥ 9.19.1, ≤ 9.19.1.24v9.20.1+1 more2024-05-22
CVE-2024-20293 [MEDIUM] CWE-436 CVE-2024-20293: A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Applian
A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to a logic error that occ
nvd
CVE-2012-0354P4HIGHCVSS 7.1v8.0v8.0\(2\)+32 more2012-03-15
CVE-2012-0354 [HIGH] CWE-20 CVE-2012-0354: The Threat Detection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and th
The Threat Detection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 through 8.2 before 8.2(5.20), 8.3 before 8.3(2.29), 8.4 before 8.4(3), 8.5 before 8.5(1.6), and 8.6 before 8.6(1.1) allows remote attackers to cause a denial of service
nvd
CVE-2026-20009P4MEDIUMCVSS 5.3≥ 9.17.1, < 9.18.4.71≥ 9.19.1, < 9.20.4.10+2 more2026-03-04
CVE-2026-20009 [MEDIUM] CWE-138 CVE-2026-20009: A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication
A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA device and execute commands as a specific user.
This vulnerability is due to insufficient va
nvd
CVE-2012-4663P4HIGHCVSS 7.1v8.3\(1\)v8.3\(2\)+8 more2012-10-29
CVE-2012-4663 [HIGH] CWE-119 CVE-2012-4663: The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and th
The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.13) and the Firewall Services Module (FWSM) 4.1 before 4.1(7) in Cisco Catalyst 6500 series switches and 760
nvd
CVE-2012-4662P4HIGHCVSS 7.1v8.3\(1\)v8.3\(2\)+8 more2012-10-29
CVE-2012-4662 [HIGH] CWE-119 CVE-2012-4662: The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and th
The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.13) and the Firewall Services Module (FWSM) 4.1 before 4.1(7) in Cisco Catalyst 6500 series switches and 760
nvd
CVE-2013-5508P4HIGHCVSS 7.1v7.0v7.0\(0\)+102 more2013-10-13
CVE-2013-5508 [HIGH] CWE-20 CVE-2013-5508: The SQL*Net inspection engine in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.1
The SQL*Net inspection engine in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.6), 9.0.x before 9.0(2.10), and 9.1.x before 9.1(2) and Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(27)
nvd
CVE-2018-15397P4MEDIUMCVSS 6.8v9.6.4v9.8.2+2 more2018-10-05
CVE-2018-15397 [MEDIUM] CWE-320 CVE-2018-15397: A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality
A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) conditio
nvd
CVE-2019-12677P4MEDIUMCVSS 6.5≥ 9.3, < 9.3.3.9fixed in 9.1.7.4+4 more2019-10-02
CVE-2019-12677 [MEDIUM] CWE-172 CVE-2019-12677: A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (
A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition that prevents the creation of new SSL/Transport Layer Security (TLS) connections to an affected device. The vulnerability is due to incorrect hand
nvd
CVE-2020-3166P4MEDIUMCVSS 6.7≥ 9.8, < 9.9.2.66≥ 9.10, < 9.13.1.52020-02-26
CVE-2020-3166 [MEDIUM] CWE-20 CVE-2020-3166: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to re
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to a specific CLI command. A successful exploit co
nvd
CVE-2026-20070P4MEDIUMCVSS 6.1v9.12.1v9.12.1.2+159 more2026-03-04
CVE-2026-20070 [MEDIUM] CWE-80 CVE-2026-20070: A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device.
This vulnerability is due
nvd