cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.

Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1

Vulnerabilities

Page 17 of 17
CVE-2026-20021P4MEDIUMCVSS 4.3≥ 9.12.1, ≤ 9.12.4.67≥ 9.16.1, ≤ 9.16.4.85+6 more2026-03-04
CVE-2026-20021 [MEDIUM] CWE-401 CVE-2026-20021: A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improperly validating
nvd
CVE-2017-3793P4MEDIUMCVSS 4.0v8.0.1.2v8.0.2+251 more2017-04-20
CVE-2017-3793 [MEDIUM] CWE-399 CVE-2017-3793: A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 throu A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 through 9.6) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause Cisco ASA and FTD to drop any further incoming traffic on all interfaces, resulting in a denial of service (DoS) condi
nvd
CVE-2005-3788P4MEDIUMCVSS 5.4v7.0\(0\)v7.0\(2\)+1 more2005-11-24
CVE-2005-3788 [MEDIUM] CVE-2005-3788: Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running w Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) by sending spoofed ARP responses from an IP address of an active firewall, which prevents the standby
nvd
CVE-2007-4786P4MEDIUMCVSS 5.3≥ 7.0, < 7.0.7.1≥ 7.1, < 7.1.2.61+2 more2007-09-10
CVE-2007-4786 [MEDIUM] CWE-319 CVE-2007-4786: Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 bef Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them over the network to a remote syslog server or places them in a local logging buffer, which al
nvd
CVE-2015-4458P4MEDIUMCVSS 4.3v9.1.5.212015-07-18
CVE-2015-4458 [MEDIUM] CWE-310 CVE-2015-4458: The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adapti The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976.
nvd
CVE-2005-3669P4MEDIUMCVSS 5.0v7.02005-11-18
CVE-2005-3669 [MEDIUM] CVE-2005-3669: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation i Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear whic
nvd
CVE-2011-2060P4MEDIUMCVSS 4.9v7.0v7.0\(0\)+69 more2011-10-22
CVE-2011-2060 [MEDIUM] CWE-399 CVE-2011-2060: The platform-sw component on Cisco Adaptive Security Appliances (ASA) 5500 series devices with softw The platform-sw component on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 before 8.2(5.3), 8.3 before 8.3(2.20), and 8.4 before 8.4(2.1) does not properly handle non-ASCII characters in an interface description, which allows local users to cause a denial of service (reload without configuration) via a crafted descript
nvd
CVE-2020-3585P4LOWCVSS 3.7fixed in 9.13.1.13≥ 9.14, < 9.14.1.302020-10-21
CVE-2020-3585 [LOW] CWE-203 CVE-2020-3585: A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper implementation of countermeasures against the Bleic
nvd
CVE-2014-2151P4MEDIUMCVSS 4.0≤ 8.4\(7.15\)2014-06-18
CVE-2014-2151 [MEDIUM] CVE-2014-2151: The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug ID CSCui04520.
nvd
CVE-2012-2474P4MEDIUMCVSS 4.0v8.2v8.2\(1\)+15 more2012-08-06
CVE-2012-2474 [MEDIUM] CWE-200 CVE-2012-2474: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 throug Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial of service (memory consumption and blank response page) by using the clientless WebVPN feature, aka Bug ID CSCth34278.
nvd