Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 2 of 17
CVE-2022-20759P2HIGHCVSS 8.8fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20759 [HIGH] CWE-266 CVE-2022-20759: A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Secur
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is due to improper separation of authentication and auth
nvd
CVE-2014-2127P3HIGHCVSS 8.5PoCv8.0v8.1+6 more2014-04-10
CVE-2014-2127 [HIGH] CWE-20 CVE-2014-2127: Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 bef
Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 before 8.6(1.13), 9.0 before 9.0(4.1), and 9.1 before 9.1(4.3) does not properly process management-session information during privilege validation for SSL VPN portal connections, which allows remote authenticated users to gain privileges
nvd
CVE-2006-0515P3HIGHCVSS 7.5PoCv7.0v7.0\(4\)+2 more2006-05-09
CVE-2006-0515 [HIGH] CVE-2006-0515: Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3
Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the request from being sent to Websense for inspe
nvd
CVE-2024-20329P2CRITICALCVSS 9.9v9.17.1v9.17.1.7+25 more2024-10-23
CVE-2024-20329 [CRITICAL] CWE-146 CVE-2024-20329: A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow
A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by submitting crafted input when executing remote CLI
nvd
CVE-2020-3125P2CRITICALCVSS 9.8≥ 9.8, < 9.8.4.15≥ 9.9, < 9.9.2.66+3 more2020-05-06
CVE-2020-3125 [CRITICAL] CWE-287 CVE-2020-3125: A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) So
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for VPN or local device access. The
nvd
CVE-2022-20866P3HIGHCVSS 7.5≥ 9.16.0, < 9.16.3.19≥ 9.17.0, < 9.17.1.13+1 more2022-08-10
CVE-2022-20866 [HIGH] CWE-203 CVE-2022-20866: A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (AS
A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in memory on a hardware platform that per
nvd
CVE-2012-4661P2CRITICALCVSS 9.0v8.3\(1\)v8.3\(2\)+10 more2012-10-29
CVE-2012-4661 [CRITICAL] CWE-119 CVE-2012-4661: Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (A
Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.34), 8.4 before 8.4(4.4), 8.5 before 8.5(1.13), and 8.6 before 8.6(1.3) and the Firewall Services Module (FWSM) 4.1 befo
nvd
CVE-2012-0358P3CRITICALCVSS 9.3v7.0v7.0\(0\)+83 more2012-03-15
CVE-2012-0358 [CRITICAL] CWE-119 CVE-2012-0358: Buffer overflow in the Cisco Port Forwarder ActiveX control in cscopf.ocx, as distributed through th
Buffer overflow in the Cisco Port Forwarder ActiveX control in cscopf.ocx, as distributed through the Clientless VPN feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 through 7.2 before 7.2(5.6), 8.0 before 8.0(5.26), 8.1 before 8.1(2.53), 8.2 before 8.2(5.18), 8.3 before 8.3(2.28), 8.2 before 8.4(2.16), and 8
nvd
CVE-2013-5511P3CRITICALCVSS 10.0v8.2v8.2\(1\)+40 more2013-10-13
CVE-2013-5511 [CRITICAL] CWE-287 CVE-2013-5511: The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security
The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.6) does not properly implement the authen
nvd
CVE-2013-5509P3CRITICALCVSS 10.0v9.0v9.12013-10-13
CVE-2013-5509 [CRITICAL] CWE-264 CVE-2013-5509: The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9
The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypass authentication, and obtain VPN access or administrative access, via a crafted X.509 client certificate, aka Bug ID CSCuf52468.
nvd
CVE-2016-6432P3HIGHCVSS 8.1v8.4.0v8.4.2+128 more2016-10-27
CVE-2016-6432 [HIGH] CWE-119 CVE-2016-6432: A vulnerability in the Identity Firewall feature of Cisco ASA Software before 9.6(2.1) could allow a
A vulnerability in the Identity Firewall feature of Cisco ASA Software before 9.6(2.1) could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to a buffer overflow in the affected code area. An attacker could exploit this vulnerability by sending a crafted NetBIOS pac
nvd
CVE-2019-1934P3HIGHCVSS 8.8≤ 8.22019-08-07
CVE-2019-1934 [HIGH] CWE-285 CVE-2019-1934: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Sof
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to elevate privileges and execute administrative functions on an affected device. The vulnerability is due to insufficient authorization validation. An attacker could exploit this vulnerability by loggin
nvd
CVE-2019-1714P3HIGHCVSS 8.6≥ 9.7, < 9.8.4≥ 9.9, < 9.9.2.50+1 more2019-05-03
CVE-2019-1714 [HIGH] CWE-255 CVE-2019-1714: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-O
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN
nvd
CVE-2017-6607P3HIGHCVSS 8.7v9.0.1v9.0.2+107 more2017-04-20
CVE-2017-6607 [HIGH] CWE-399 CVE-2017-6607: A vulnerability in the DNS code of Cisco ASA Software could allow an unauthenticated, remote attacke
A vulnerability in the DNS code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause an affected device to reload or corrupt the information present in the device's local DNS cache. The vulnerability is due to a flaw in handling crafted DNS response messages. An attacker could exploit this vulnerability by triggering a DNS requ
nvd
CVE-2017-12246P3HIGHCVSS 8.6v9.4\(3\)v9.7\(1\)+1 more2017-10-05
CVE-2017-12246 [HIGH] CWE-399 CVE-2017-12246: A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Securit
A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of the HTTP header.
nvd
CVE-2026-20082P3HIGHCVSS 8.6≥ 9.20.4.14, < 9.20.4.192026-03-04
CVE-2026-20082 [HIGH] CWE-772 CVE-2026-20082: A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive
A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause incoming TCP SYN packets to be dropped incorrectly.
This vulnerability is due to improper handling of new, incoming TCP connections that are destined to manageme
nvd
CVE-2026-20103P3HIGHCVSS 8.6≥ 9.12.1, < 9.16.4.85≥ 9.17.1, < 9.18.4.66+3 more2026-03-04
CVE-2026-20103 [HIGH] CWE-770 CVE-2026-20103: A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access SSL VPN connections. This does no
nvd
CVE-2020-3304P3HIGHCVSS 8.6≥ 9.8.0, < 9.8.4.22≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3304 [HIGH] CWE-400 CVE-2020-3304: A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepow
A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP re
nvd
CVE-2018-15465P3HIGHCVSS 8.1fixed in 9.4.4.29≥ 9.5, < 9.6.4.20+3 more2018-12-24
CVE-2018-15465 [HIGH] CWE-285 CVE-2018-15465: A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software c
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interfa
nvd
CVE-2019-15992P3HIGHCVSS 7.2≥ 9.7, < 9.8.4.15≥ 9.9, < 9.9.2.61+5 more2020-09-23
CVE-2019-15992 [HIGH] CWE-119 CVE-2019-15992: A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security A
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an affected device. The vulnerability is d
nvd