Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 16 of 17
CVE-2015-4239P4MEDIUMCVSS 6.1v100.13\(0.21\)v9.3\(2.243\)2015-07-03
CVE-2015-4239 [MEDIUM] CWE-399 CVE-2015-4239: Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers
Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.
nvd
CVE-2009-5037P4MEDIUMCVSS 5.0≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2009-5037 [MEDIUM] CWE-399 CVE-2009-5037: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allow remot
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allow remote attackers to cause a denial of service (ASDM syslog outage) via a long URL, aka Bug IDs CSCsm11264 and CSCtb92911.
nvd
CVE-2010-4690P4MEDIUMCVSS 5.0≤ 8.3\(1\)v7.0+56 more2011-01-07
CVE-2010-4690 [MEDIUM] CWE-287 CVE-2010-4690: The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devic
The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly authenticate HTTP requests from a Web Security appliance (WSA), which might allow remote attackers to obtain sensitive information via a HEAD request, aka Bug ID CSCte53635.
nvd
CVE-2014-3407P4MEDIUMCVSS 5.0≤ 9.3\(2\)2014-11-28
CVE-2014-3407 [MEDIUM] CWE-400 CVE-2014-3407: The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier d
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.
nvd
CVE-2015-0760P4MEDIUMCVSS 4.0≥ 7.0, < 8.2.2.132015-06-04
CVE-2015-0760 [MEDIUM] CWE-20 CVE-2015-0760: The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows r
The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259.
nvd
CVE-2018-15398P4MEDIUMCVSS 4.0v9.6\(4.3\)v9.4\(2\)+1 more2018-10-05
CVE-2018-15398 [MEDIUM] CWE-284 CVE-2018-15398: A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an affected device. The vulnerability is due to errors that could occur wh
nvd
CVE-2014-3390P4MEDIUMCVSS 6.8v8.7.8v8.7.1+10 more2014-10-10
CVE-2014-3390 [MEDIUM] CWE-20 CVE-2014-3390: The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 before
The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 before 8.7(1.14), 9.2 before 9.2(2.8), and 9.3 before 9.3(1.1) allows local users to obtain Linux root access by leveraging administrative privileges and executing a crafted script, aka Bug IDs CSCuq41510 and CSCuq47574.
nvd
CVE-2023-20275P4MEDIUMCVSS 4.3v9.8.1v9.8.1.5+164 more2023-12-12
CVE-2023-20275 [MEDIUM] CWE-346 CVE-2023-20275: A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Softwar
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the packet's inner source IP address after
nvd
CVE-2008-2057P4MEDIUMCVSS 5.4v7.2.2v8.02008-06-04
CVE-2008-2057 [MEDIUM] CVE-2008-2057: The Instant Messenger (IM) inspection engine in Cisco Adaptive Security Appliance (ASA) and Cisco PI
The Instant Messenger (IM) inspection engine in Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(4), 8.0.x before 8.0(3)10, and 8.1.x before 8.1(1)2 allows remote attackers to cause a denial of service via a crafted packet.
nvd
CVE-2010-4677P4MEDIUMCVSS 5.0≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2010-4677 [MEDIUM] CWE-399 CVE-2010-4677: emWEB on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) al
emWEB on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (daemon crash) via a request for a document whose name contains space characters, aka Bug ID CSCsy08416.
nvd
CVE-2013-1138P4MEDIUMCVSS 5.0v7.0v7.0\(0\)+86 more2013-02-25
CVE-2013-1138 [MEDIUM] CWE-119 CVE-2013-1138: The NAT process on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause
The NAT process on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (connections-table memory consumption) via crafted packets, aka Bug ID CSCue46386.
nvd
CVE-2019-12693P4MEDIUMCVSS 4.9≥ 9.7, < 9.8.4≥ 9.9, < 9.9.2.50+2 more2019-10-02
CVE-2019-12693 [MEDIUM] CWE-704 CVE-2019-12693: A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the use of an incorrect data type for a length variable. An attacker could exploit this vulnerability by initiating the transfer o
nvd
CVE-2017-6770P4MEDIUMCVSS 4.2v7.0.1v7.0.1.4+345 more2017-08-07
CVE-2017-6770 [MEDIUM] CWE-20 CVE-2017-6770: Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS
Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an unauthenticated, remote attacker to t
nvd
CVE-2026-20069P4MEDIUMCVSS 4.3≥ 9.12.1, < 9.16.4.85≥ 9.17.1, < 9.18.4.66+3 more2026-03-04
CVE-2026-20069 [MEDIUM] CWE-444 CVE-2026-20069: A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device.
This vulnerability is due to improper validation of HTTP r
nvd
CVE-2006-3906P4MEDIUMCVSS 5.0v7.0v7.0\(4\)+4 more2006-07-27
CVE-2006-3906 [MEDIUM] CVE-2006-3906: Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators,
Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a design weakness of the IKE version 1 protoc
nvd
CVE-2013-6707P4MEDIUMCVSS 4.3≤ 9.1\(3\)2013-12-07
CVE-2013-6707 [MEDIUM] CWE-772 CVE-2013-6707: Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Soft
Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to cause a denial of service (multi-protocol management outage) by making multiple management session requests, aka Bug ID CSCug33233.
nvd
CVE-2019-1701P4MEDIUMCVSS 4.8fixed in 9.4.4.34≥ 9.5, < 9.6.4.25+3 more2019-05-03
CVE-2019-1701 [MEDIUM] CWE-79 CVE-2019-1701: Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software a
Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal of an affected device. The vulnerabilities exist because the software insuff
nvd
CVE-2015-4550P4MEDIUMCVSS 4.3v9.3\(3\)v9.4\(1.1\)2015-06-17
CVE-2015-4550 [MEDIUM] CWE-310 CVE-2015-4550: The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with sof
The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.
nvd
CVE-2014-3391P4MEDIUMCVSS 6.8v8.7.8v8.2.0.45+64 more2014-10-10
CVE-2014-3391 [MEDIUM] CWE-20 CVE-2014-3391: Untrusted search path vulnerability in Cisco ASA Software 8.x before 8.4(3), 8.5, and 8.7 before 8.7
Untrusted search path vulnerability in Cisco ASA Software 8.x before 8.4(3), 8.5, and 8.7 before 8.7(1.13) allows local users to gain privileges by placing a Trojan horse library file in external memory, leading to library use after device reload because of an incorrect LD_LIBRARY_PATH value, aka Bug ID CSCtq52661.
nvd
CVE-2011-3309P4MEDIUMCVSS 4.3v8.2\(1\)v8.2\(2\)+18 more2012-05-02
CVE-2011-3309 [MEDIUM] CWE-200 CVE-2011-3309: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 process I
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 process IKE requests despite a vpnclient mode configuration, which allows remote attackers to obtain potentially sensitive information by reading IKE responder traffic, aka Bug ID CSCtt07749.
nvd