cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.

Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1

Vulnerabilities

Page 15 of 17
CVE-2015-6379P4MEDIUMCVSS 6.8v8.4.02015-11-25
CVE-2015-6379 [MEDIUM] CWE-399 CVE-2015-6379: The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 a The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.
nvd
CVE-2014-0739P4MEDIUMCVSS 4.3v9.1\(3\)2014-02-22
CVE-2014-0739 [MEDIUM] CWE-287 CVE-2014-0739: Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1( Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766.
nvd
CVE-2013-6682P4MEDIUMCVSS 6.4≤ 9.0.3\(6\)v7.0+109 more2013-11-13
CVE-2013-6682 [MEDIUM] CWE-20 CVE-2013-6682: The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earli The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid entry, aka Bug ID CSCui33299.
nvd
CVE-2020-3599P4MEDIUMCVSS 6.1≥ 9.7.0, < 9.8.4.29≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3599 [MEDIUM] CWE-79 CVE-2020-3599: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Sof A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An
nvd
CVE-2016-1295P4MEDIUMCVSS 5.3v8.4.0v8.4.1+24 more2016-01-16
CVE-2016-1295 [MEDIUM] CWE-200 CVE-2016-1295: Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive inf Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.
nvd
CVE-2026-20024P4MEDIUMCVSS 5.7v9.12.1v9.12.1.2+139 more2026-03-04
CVE-2026-20024 [MEDIUM] CWE-119 CVE-2026-20024: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key. This vulnerability is due to heap corrupt
nvd
CVE-2008-0028P4HIGHCVSS 7.1fixed in 7.2\(3\)6v8.0\(3\)2008-01-23
CVE-2008-0028 [HIGH] CVE-2008-0028: Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Securi Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet.
nvd
CVE-2007-5569P4HIGHCVSS 7.1v7.12007-10-18
CVE-2007-5569 [HIGH] CWE-20 CVE-2007-5569: Cisco PIX and ASA appliances with 7.1 and 7.2 software, when configured for TLS sessions to the devi Cisco PIX and ASA appliances with 7.1 and 7.2 software, when configured for TLS sessions to the device, allow remote attackers to cause a denial of service (device reload) via a crafted TLS packet, aka CSCsg43276 and CSCsh97120.
nvd
CVE-2014-3399P4MEDIUMCVSS 5.5≤ 9.2\(2.4\)2014-10-07
CVE-2014-3399 [MEDIUM] CWE-94 CVE-2014-3399: The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cache files or inject Lua programs, and consequently cause a denial of service (portal outage or s
nvd
CVE-2011-3285P4MEDIUMCVSS 5.0v8.0v8.0\(2\)+28 more2012-05-02
CVE-2011-3285 [MEDIUM] CWE-20 CVE-2011-3285: CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCth63101.
nvd
CVE-2017-6764P4MEDIUMCVSS 5.4v9.5\(1\)2017-08-07
CVE-2017-6764 [MEDIUM] CWE-79 CVE-2017-6764: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5 A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the
nvd
CVE-2020-3561P4MEDIUMCVSS 4.7≥ 9.8.0, < 9.8.4.20≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3561 [MEDIUM] CWE-93 CVE-2020-3561: A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Softwa A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the affected system. The vulnerability is due to improper input sanitization. An attacker could expl
nvd
CVE-2015-6423P4MEDIUMCVSS 4.3v9.4.1v9.4.1.1+5 more2016-01-15
CVE-2015-6423 [MEDIUM] CWE-264 CVE-2015-6423: The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 throu The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remote authenticated users to bypass an intended DCERPC-only ACL by sending arbitrary network traffic, aka Bug ID CSCuu67782.
nvd
CVE-2016-6424P4MEDIUMCVSS 6.5v8.4.7.29v9.1\(7\)42016-10-06
CVE-2016-6424 [MEDIUM] CWE-399 CVE-2016-6424: The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7 The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942.
nvd
CVE-2012-5717P4MEDIUMCVSS 6.3v8.0v8.0\(2\)+26 more2013-01-18
CVE-2012-5717 [MEDIUM] CWE-264 CVE-2012-5717: Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly ma Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authenticated users to cause a denial of service (device crash) by establishing multiple sessions, aka Bug ID CSCtc59462.
nvd
CVE-2012-0335P4MEDIUMCVSS 5.0v7.2v7.2\(1\)+41 more2012-05-02
CVE-2012-0335 [MEDIUM] CWE-287 CVE-2012-0335: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not pr Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection attempt, aka Bug ID CSCtx42746.
nvd
CVE-2007-2464P4HIGHCVSS 7.1≤ 7.2.2v7.12007-05-02
CVE-2007-2464 [HIGH] CVE-2007-2464: Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allows remote attackers to cause a denial of service (device reload) via "non-standard SSL sessions."
nvd
CVE-2014-8023P4MEDIUMCVSS 4.0≤ 9.2.32015-02-17
CVE-2014-8023 [MEDIUM] CWE-264 CVE-2014-8023: Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authen Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, does not properly select tunnel groups, which allows remote authenticated users to bypass intended resource-access restrictions via a crafted tunnel-group parameter, aka Bug ID CSCtz48533.
nvd
CVE-2023-20247P4MEDIUMCVSS 4.3v9.8.1v9.8.1.5+160 more2023-11-01
CVE-2023-20247 [MEDIUM] CWE-288 CVE-2023-20247: A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Soft A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and password. This vulnerability is due to i
nvd
CVE-2015-4241P4MEDIUMCVSS 6.1v9.3\(2\)2015-07-08
CVE-2015-4241 [MEDIUM] CVE-2015-4241: Cisco Adaptive Security Appliance (ASA) Software 9.3(2) allows remote attackers to cause a denial of Cisco Adaptive Security Appliance (ASA) Software 9.3(2) allows remote attackers to cause a denial of service (system reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCut52679.
nvd