cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.

Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1

Vulnerabilities

Page 12 of 17
CVE-2012-0378P4HIGHCVSS 7.8v8.0v8.0\(2\)+28 more2012-05-03
CVE-2012-0378 [HIGH] CWE-189 CVE-2012-0378: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allow rem Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allow remote attackers to cause a denial of service (connection limit exceeded) by triggering a large number of stale connections that result in an incorrect value for an MPF connection count, aka Bug ID CSCtv19854.
nvd
CVE-2015-6325P4HIGHCVSS 7.1v7.2.1v7.2.1.9+173 more2015-10-25
CVE-2015-6325 [HIGH] CWE-399 CVE-2015-6325: Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8. Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.4), 9.2 before 9.2(4), 9.3 before 9.3(3.1), and 9.4 before 9.4(1.1) allows remote attackers to cause a denial of service (device reload) via a crafted DNS response, aka Bug
nvd
CVE-2015-6324P4HIGHCVSS 7.1v9.0.1v9.0.2+47 more2015-10-25
CVE-2015-6324 [HIGH] CWE-399 CVE-2015-6324: The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) software 9.0 before 9.0(4 The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) software 9.0 before 9.0(4.37), 9.1 before 9.1(6.6), 9.2 before 9.2(4), 9.3 before 9.3(3.5), and 9.4 before 9.4(2) allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug IDs CSCus56252 and CSCus57142.
nvd
CVE-2013-5513P4HIGHCVSS 7.1v8.2v8.2\(1\)+29 more2013-10-13
CVE-2013-5513 [HIGH] CWE-119 CVE-2013-5513: Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4 Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(7), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.3), and 9.1.x before 9.1(1.8), when the DNS ALPI engine is enabled for TCP, allows remote attackers to cause a denial of service (device reload) vi
nvd
CVE-2022-20826P4MEDIUMCVSS 6.8v9.17.1v9.17.1.9+4 more2022-11-15
CVE-2022-20826 [MEDIUM] CWE-501 CVE-2022-20826: A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are run A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This vulnerability is due to a l
nvd
CVE-2018-0251P4MEDIUMCVSS 6.1v9.8\(2.15\)v9.9\(1\)2018-04-19
CVE-2018-0251 [MEDIUM] CWE-79 CVE-2018-0251: A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets La A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of that portal on an affected device. The vulnerability is due to insuf
nvd
CVE-2021-1488P4MEDIUMCVSS 6.7≥ 9.13, < 9.13.1.21≥ 9.14, < 9.14.2.13+1 more2021-04-29
CVE-2021-1488 [MEDIUM] CWE-77 CVE-2021-1488: A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS). This vulnerability is due to insufficient input validation. An a
nvd
CVE-2019-1695P4MEDIUMCVSS 6.5fixed in 9.8.4≥ 9.9, < 9.9.2.50+1 more2019-05-03
CVE-2019-1695 [MEDIUM] CWE-284 CVE-2019-1695: A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected d
nvd
CVE-2026-20022P4MEDIUMCVSS 6.5v9.12.1v9.12.1.2+161 more2026-03-04
CVE-2026-20022 [MEDIUM] CWE-823 CVE-2026-20022: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf canon. This vulnerability is due to
nvd
CVE-2017-3867P4MEDIUMCVSS 5.3v6.3.1v9.6.2+7 more2017-03-17
CVE-2017-3867 [MEDIUM] CWE-287 CVE-2017-3867: A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implem A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to bypass the access control list (ACL) for specific TCP and UDP traffic. More Information: CSCvc68229. Known Affected Releases: 9.6(2). Known F
nvd
CVE-2020-3564P4MEDIUMCVSS 5.3≥ 9.8.0, < 9.8.4.26≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3564 [MEDIUM] CWE-284 CVE-2020-3564: A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection. The vulnerability is due to ineffective flow tracking of FTP traffic. An attacker could exploit this vulnerability by sending crafte
nvd
CVE-2014-2128P4MEDIUMCVSS 5.0v8.2v8.3\(1\)+4 more2014-04-10
CVE-2014-2128 [MEDIUM] CWE-287 CVE-2014-2128: The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication via (1) a crafted cookie value within modified HTTP POST data or (2) a crafted URL, aka Bug ID
nvd
CVE-2014-2129P4HIGHCVSS 7.1v8.2v8.4+2 more2014-04-10
CVE-2014-2129 [HIGH] CWE-20 CVE-2014-2129: The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5), 9.0 before 9.0(3.1), and 9.1 before 9.1(2.5) allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted SIP packets, aka Bug ID CSCuh44052.
nvd
CVE-2013-5512P4HIGHCVSS 7.1v8.2v8.2\(1\)+31 more2013-10-13
CVE-2013-5512 [HIGH] CWE-362 CVE-2013-5512: Race condition in the HTTP Deep Packet Inspection (DPI) feature in Cisco Adaptive Security Appliance Race condition in the HTTP Deep Packet Inspection (DPI) feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.5), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.4), 9.0.x before 9.0(1.4), and 9.1.x before 9.1(1.2), in certain conditions involving the spoof-serve
nvd
CVE-2020-3458P4MEDIUMCVSS 6.7≥ 9.8.0, < 9.8.4.26≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3458 [MEDIUM] CWE-693 CVE-2020-3458: Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Softw Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass the secure boot mechanism. The vulnerabilities are due to insufficient protections
nvd
CVE-2018-0242P4MEDIUMCVSS 6.1v9.1\(7.245\)v9.6\(3\)+2 more2018-04-19
CVE-2018-0242 [MEDIUM] CWE-79 CVE-2018-0242: A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance co A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web
nvd
CVE-2019-1705P4MEDIUMCVSS 5.9≥ 9.4, < 9.4.4.34≥ 9.5, < 9.6.4.25+3 more2019-05-03
CVE-2019-1705 [MEDIUM] CWE-404 CVE-2019-1705: A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulner
nvd
CVE-2024-20341P4MEDIUMCVSS 6.1v9.8.1v9.8.1.5+186 more2024-10-23
CVE-2024-20341 [MEDIUM] CWE-80 CVE-2024-20341: A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) So A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper valida
nvd
CVE-2024-20382P4MEDIUMCVSS 6.1v9.8.1v9.8.1.5+199 more2024-10-23
CVE-2024-20382 [MEDIUM] CWE-80 CVE-2024-20382: A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) So A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper valida
nvd
CVE-2023-20264P4MEDIUMCVSS 6.1≥ 9.18.1, ≤ 9.18.3.46≥ 9.19.1.5, ≤ 9.19.1.122023-11-01
CVE-2023-20264 [MEDIUM] CWE-601 CVE-2023-20264: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-o A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user who is authenticating to a re
nvd