Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 13 of 17
CVE-2026-20102P4MEDIUMCVSS 6.1≥ 9.16.1, < 9.16.4.89≥ 9.17.1, < 9.18.4.71+3 more2026-03-04
CVE-2026-20102 [MEDIUM] CWE-79 CVE-2026-20102: A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software a
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based information.
This vulnerability is due t
nvd
CVE-2016-1445P4MEDIUMCVSS 5.3≥ 8.2, < 9.4.3.3≥ 9.5.0, < 9.5.2.10+1 more2016-07-12
CVE-2016-1445 [MEDIUM] CVE-2016-1445: Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypa
Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.
nvd
CVE-2021-34787P4MEDIUMCVSS 5.3≥ 9.9.0, < 9.12.4.25≥ 9.13.0, < 9.14.3.1+2 more2021-10-27
CVE-2021-34787 [MEDIUM] CWE-183 CVE-2021-34787: A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Secu
A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices conf
nvd
CVE-2021-34794P4MEDIUMCVSS 5.3≥ 9.14.0, < 9.14.2.4≥ 9.15.0, < 9.15.1.72021-10-27
CVE-2021-34794 [MEDIUM] CWE-284 CVE-2021-34794: A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control function
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could
nvd
CVE-2026-20106P4MEDIUMCVSS 5.3≥ 9.12.1, < 9.16.4.85≥ 9.17.1, < 9.18.4.66+3 more2026-03-04
CVE-2026-20106 [MEDIUM] CWE-401 CVE-2026-20106: A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure
A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition requiring a manual reboot.
nvd
CVE-2015-4238P4MEDIUMCVSS 6.8v8.4\(7\)v8.6\(1.2\)2015-07-02
CVE-2015-4238 [MEDIUM] CWE-399 CVE-2015-4238: The SNMP implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4(7) and 8.6(1.2) allo
The SNMP implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4(7) and 8.6(1.2) allows remote authenticated users to cause a denial of service (device reload) by sending many SNMP requests during a time of high network traffic, aka Bug ID CSCul02601.
nvd
CVE-2013-1151P4HIGHCVSS 7.1v7.0v7.0\(0\)+80 more2013-04-11
CVE-2013-1151 [HIGH] CWE-20 CVE-2013-1151: Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(
Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5), 8.5 before 8.5(1.17), 8.6 before 8.6(1.10), and 8.7 before 8.7(1.3) allow remote attackers to cause a denial of service (device reload) via a crafted certificate, aka Bug ID CSCu
nvd
CVE-2016-1385P4MEDIUMCVSS 6.5v8.4.0v8.4.1+128 more2016-05-26
CVE-2016-1385 [MEDIUM] CWE-119 CVE-2016-1385: The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authe
The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authenticated users to cause a denial of service (instability, memory consumption, or device reload) by leveraging (1) administrative access or (2) Clientless SSL VPN access to provide a crafted XML document, aka Bug ID CSCut14209.
nvd
CVE-2022-20713P4MEDIUMCVSS 6.1v9.8.1v9.8.1.5+148 more2022-08-10
CVE-2022-20713 [MEDIUM] CWE-444 CVE-2022-20713: A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA)
A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of input that is passed to
nvd
CVE-2026-20023P4MEDIUMCVSS 6.5v9.12.1v9.12.1.2+157 more2026-03-04
CVE-2026-20023 [MEDIUM] CWE-787 CVE-2026-20023: A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to corrupt memory on an affected device, resulting in a denial of service (DoS) condition.
This vulnerability is due to memory corruption wh
nvd
CVE-2023-20081P4MEDIUMCVSS 5.9v9.8.1v9.8.1.5+157 more2023-03-23
CVE-2023-20081 [MEDIUM] CWE-122 CVE-2023-20081: A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) S
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu
nvd
CVE-2021-34791P4MEDIUMCVSS 5.3≥ 9.12.0, < 9.12.4.18≥ 9.13.0, < 9.14.2.15+1 more2021-10-27
CVE-2021-34791 [MEDIUM] CWE-358 CVE-2021-34791: Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For mo
nvd
CVE-2021-34790P4MEDIUMCVSS 5.3≥ 9.12.0, < 9.12.4.29≥ 9.13.0, < 9.14.2.15+1 more2021-10-27
CVE-2021-34790 [MEDIUM] CWE-358 CVE-2021-34790: Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For mo
nvd
CVE-2007-5568P4HIGHCVSS 7.1v7.0v7.0\(4\)+22 more2007-10-18
CVE-2007-5568 [HIGH] CWE-20 CVE-2007-5568: Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM
Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (FWSM).
nvd
CVE-2013-5507P4HIGHCVSS 7.1v9.12013-10-13
CVE-2013-5507 [HIGH] CWE-310 CVE-2013-5507: The IPsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(1.7), wh
The IPsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(1.7), when an IPsec VPN tunnel is enabled, allows remote attackers to cause a denial of service (device reload) via a (1) ICMP or (2) ICMPv6 packet that is improperly handled during decryption, aka Bug ID CSCue18975.
nvd
CVE-2013-6691P4MEDIUMCVSS 6.8≤ 9.0\(4.1\)2014-07-14
CVE-2013-6691 [MEDIUM] CWE-119 CVE-2013-6691: The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and ear
The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial of service (device reload) via a long share list, aka Bug ID CSCuj83344.
nvd
CVE-2016-1379P4MEDIUMCVSS 6.5v9.0.1v9.0.2+66 more2016-05-28
CVE-2016-1379 [MEDIUM] CWE-399 CVE-2016-1379: Cisco Adaptive Security Appliance (ASA) Software 9.0 through 9.5.1 mishandles IPsec error processing
Cisco Adaptive Security Appliance (ASA) Software 9.0 through 9.5.1 mishandles IPsec error processing, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted (1) LAN-to-LAN or (2) Remote Access VPN tunnel packets, aka Bug ID CSCuv70576.
nvd
CVE-2026-20025P4MEDIUMCVSS 6.8≥ 9.12.1, < 9.16.4.85≥ 9.17.1, < 9.18.4.66+3 more2026-03-04
CVE-2026-20025 [MEDIUM] CWE-190 CVE-2026-20025: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key.
This vulnerability is due to insufficient
nvd
CVE-2020-3582P4MEDIUMCVSS 6.1fixed in 9.8.4.26≥ 9.9, < 9.9.2.80+4 more2020-10-21
CVE-2020-3582 [MEDIUM] CWE-79 CVE-2020-3582: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3581P4MEDIUMCVSS 6.1fixed in 9.8.4.29≥ 9.9, < 9.9.2.80+4 more2020-10-21
CVE-2020-3581 [MEDIUM] CWE-79 CVE-2020-3581: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd