Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 14 of 17
CVE-2020-3583P4MEDIUMCVSS 6.1≥ 9.7, < 9.8.4.29≥ 9.9, < 9.9.2.80+4 more2020-10-21
CVE-2020-3583 [MEDIUM] CWE-79 CVE-2020-3583: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2026-20020P4MEDIUMCVSS 5.7v9.12.1v9.12.1.2+145 more2026-03-04
CVE-2026-20020 [MEDIUM] CWE-20 CVE-2026-20020: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. If OSPF authentication is enabled, the attacker must know the secret key to exploit this vulnerability.
This vulner
nvd
CVE-2015-4321P4MEDIUMCVSS 5.0v9.3\(1.50\)v9.3\(2.100\)+2 more2015-08-20
CVE-2015-4321 [MEDIUM] CWE-20 CVE-2015-4321: The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA)
The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(1.50), 9.3(2.100), 9.3(3), and 9.4(1) mishandles cases where an IP address belongs to an internal interface but is also in the ASA routing table, which allows remote attackers to bypass uRPF validation via spoofed packets, aka Bug ID CSCuv6
nvd
CVE-2024-20493P4MEDIUMCVSS 5.3v9.8.1v9.8.1.5+201 more2024-10-23
CVE-2024-20493 [MEDIUM] CWE-772 CVE-2024-20493: A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Ci
A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in a temporary denial of service (
nvd
CVE-2024-20526P4MEDIUMCVSS 5.3v9.16.4.67v9.16.4.70+2 more2024-10-23
CVE-2024-20526 [MEDIUM] CWE-400 CVE-2024-20526: A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an
A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server of an affected device.
This vulnerability is due to a logic error when an SSH session is established. An attacker could exploit this vulnerability by sen
nvd
CVE-2010-4676P4MEDIUMCVSS 6.8≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2010-4676 [MEDIUM] CWE-399 CVE-2010-4676: Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with softw
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote authenticated users to cause a denial of service (device crash) via a high volume of IPsec traffic, aka Bug ID CSCsx52748.
nvd
CVE-2013-5568P4HIGHCVSS 7.1≤ 9.0.3\(6\)v7.0+109 more2013-11-13
CVE-2013-5568 [HIGH] CWE-20 CVE-2013-5568: The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earli
The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of service (device reload) via crafted update data, aka Bug ID CSCui33308.
nvd
CVE-2015-0676P4HIGHCVSS 7.1v7.0.1v7.0.1.4+239 more2015-04-13
CVE-2015-0676 [HIGH] CWE-20 CVE-2015-0676: The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2
The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 before 9.1(6.1), 9.2 before 9.2(3.4), and 9.3 before 9.3(3) allows man-in-the-middle attackers to cau
nvd
CVE-2024-20355P4MEDIUMCVSS 5.0v9.8.2.28v9.8.2.33+151 more2024-05-22
CVE-2024-20355 [MEDIUM] CWE-862 CVE-2024-20355: A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN service
A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to successfully establish a VPN session on an affected device. This vulnerability is due to improper
nvd
CVE-2013-5510P4MEDIUMCVSS 4.3v7.0v7.0\(0\)+82 more2013-10-13
CVE-2013-5510 [MEDIUM] CWE-287 CVE-2013-5510: The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before
The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.5), when an override-account-disable option is enabled, does not properly parse AAA LDAP responses, which
nvd
CVE-2007-2461P4HIGHCVSS 7.8v7.2.22007-05-02
CVE-2007-2461 [HIGH] CVE-2007-2461: The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers
The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM message that causes multiple DHCPACK messages to be sent from DHCP servers to the agent, which consumes the memory allocated for a local buffer. NOTE: this issue only occurs when multip
nvd
CVE-2013-5557P4MEDIUMCVSS 6.3≤ 9.1\(2\)2015-02-07
CVE-2013-5557 [MEDIUM] CVE-2013-5557: The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Applian
The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP request that triggers a rewrite, aka Bug ID CSCug91577.
nvd
CVE-2012-6395P4MEDIUMCVSS 6.3v8.42013-01-18
CVE-2012-6395 [MEDIUM] CWE-20 CVE-2012-6395: Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecif
Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to UNC share pathnames, which allows remote authenticated users to cause a denial of service (device crash) via unknown vectors, aka Bug ID CSCuc65775.
nvd
CVE-2014-3264P4MEDIUMCVSS 6.3≤ 9.1\(5\)2014-05-20
CVE-2014-3264 [MEDIUM] CVE-2014-3264: Cisco Adaptive Security Appliance (ASA) Software 9.1(.5) and earlier allows remote authenticated use
Cisco Adaptive Security Appliance (ASA) Software 9.1(.5) and earlier allows remote authenticated users to cause a denial of service (device reload) via crafted attributes in a RADIUS packet, aka Bug ID CSCun69561.
nvd
CVE-2017-6765P4MEDIUMCVSS 6.1v9.1\(6.11\)v9.4\(1.2\)2017-08-07
CVE-2017-6765 [MEDIUM] CWE-79 CVE-2017-6765: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.1
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.1(6.11) and 9.4(1.2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka WebVPN XSS. The vulnerability is due to insufficient valida
nvd
CVE-2019-12695P4MEDIUMCVSS 6.1≥ 9.7, < 9.8.4.9≥ 9.9, < 9.9.2.56+3 more2019-10-02
CVE-2019-12695 [MEDIUM] CWE-79 CVE-2019-12695: A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA)
A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to in
nvd
CVE-2015-0742P4MEDIUMCVSS 5.0v9.2\(3.4\)v9.4\(0.115\)+9 more2015-05-21
CVE-2015-0742 [MEDIUM] CWE-399 CVE-2015-0742: The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Soft
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registration, which allows remote attackers to cause a denial o
nvd
CVE-2013-5567P4MEDIUMCVSS 5.4≤ 8.4\(6\)2014-07-14
CVE-2013-5567 [MEDIUM] CWE-400 CVE-2013-5567: Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported conf
Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering and inspection, allows remote attackers to cause a denial of service (traffic loop and device crash) via a packet that triggers multiple matches, aka Bug ID CSCui45606.
nvd
CVE-2013-5560P4MEDIUMCVSS 5.4≤ 9.1\(3\)v7.0+113 more2013-11-13
CVE-2013-5560 [MEDIUM] CWE-20 CVE-2013-5560: The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when
The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly process NAT rules, which allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCue34342.
nvd
CVE-2014-3394P4MEDIUMCVSS 5.0v8.2.0.45v8.2.1+68 more2014-10-10
CVE-2014-3394 [MEDIUM] CWE-295 CVE-2014-3394: The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an arbitrary VeriSign certificate, aka Bug ID CSCun10916.
nvd