Cisco Adaptive Security Appliance Software vulnerabilities
306 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
306
CISA KEV
12
actively exploited
Public exploits
12
Exploited in wild
11
Severity breakdown
CRITICAL15HIGH177MEDIUM113LOW1
Vulnerabilities
Page 3 of 16
CVE-2022-20924MEDIUMCVSS 6.5v9.14.1v9.14.1.6+39 more2022-11-15
CVE-2022-20924 [MEDIUM] CWE-703 CVE-2022-20924: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation. An
nvd
CVE-2022-20928MEDIUMCVSS 5.8v9.6.1v9.6.1.3+216 more2022-11-15
CVE-2022-20928 [MEDIUM] CWE-863 CVE-2022-20928: A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive
A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user.
This vulnerability is due to a flaw in the authorization verifications during t
nvd
CVE-2022-20826MEDIUMCVSS 6.8v9.17.1v9.17.1.9+4 more2022-11-15
CVE-2022-20826 [MEDIUM] CWE-501 CVE-2022-20826: A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are run
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality.
This vulnerability is due to a l
nvd
CVE-2022-20927MEDIUMCVSS 6.5v9.13.1v9.13.1.2+32 more2022-11-15
CVE-2022-20927 [MEDIUM] CWE-120 CVE-2022-20927: A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper memory management when a device initiates SSL/TLS connection
nvd
CVE-2022-20866HIGHCVSS 7.5≥ 9.16.0, < 9.16.3.19≥ 9.17.0, < 9.17.1.13+1 more2022-08-10
CVE-2022-20866 [HIGH] CWE-203 CVE-2022-20866: A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (AS
A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in memory on a hardware platform that per
nvd
CVE-2022-20713MEDIUMCVSS 6.1v9.8.1v9.8.1.5+148 more2022-08-10
CVE-2022-20713 [MEDIUM] CWE-444 CVE-2022-20713: A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA)
A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of input that is passed to
nvd
CVE-2022-20742HIGHCVSS 7.4fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20742 [HIGH] CWE-325 CVE-2022-20742: A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisc
A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerability is due to an improper implementation of Galois/Counter Mode (GCM) ciphers. An attacker
nvd
CVE-2022-20759HIGHCVSS 8.8fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20759 [HIGH] CWE-266 CVE-2022-20759: A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Secur
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is due to improper separation of authentication and auth
nvd
CVE-2022-20760HIGHCVSS 7.5fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20760 [HIGH] CWE-400 CVE-2022-20760: A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to a lack of proper processing of incoming requests. An attacker coul
nvd
CVE-2022-20745HIGHCVSS 7.5fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20745 [HIGH] CWE-20 CVE-2022-20745: A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Secur
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS request
nvd
CVE-2022-20715HIGHCVSS 8.6fixed in 9.8.4.44≥ 9.9, < 9.12.4.38+4 more2022-05-03
CVE-2022-20715 [HIGH] CWE-399 CVE-2022-20715: A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Sof
A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation of errors that are logged as a r
nvd
CVE-2022-20737HIGHCVSS 7.1fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20737 [HIGH] CWE-122 CVE-2022-20737: A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless
A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device or to obtain portions of process memory from an affected device. This vu
nvd
CVE-2022-20795HIGHCVSS 7.5≥ 9.17.0, ≤ 9.17.1.92022-04-21
CVE-2022-20795 [HIGH] CWE-345 CVE-2022-20795: A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security
A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processi
nvd
CVE-2021-1573HIGHCVSS 7.5≥ 9.8, < 9.8.4.40≥ 9.9, < 9.12.4.26+3 more2022-01-11
CVE-2021-1573 [HIGH] CWE-121 CVE-2021-1573: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit t
nvd
CVE-2021-34704HIGHCVSS 7.5≥ 9.15, < 9.15.1.17≥ 9.16, < 9.16.22022-01-11
CVE-2021-34704 [HIGH] CWE-121 CVE-2021-34704: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2021-34792HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.40≥ 9.12.0, < 9.12.4.29+3 more2021-10-27
CVE-2021-34792 [HIGH] CWE-400 CVE-2021-34792: A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Fir
A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacke
nvd
CVE-2021-34783HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.40≥ 9.12.0, < 9.12.4.29+3 more2021-10-27
CVE-2021-34783 [HIGH] CWE-119 CVE-2021-34783: A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (
A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient validation of SS
nvd
CVE-2021-34793HIGHCVSS 8.6≥ 9.9.0, < 9.12.4.29≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-34793 [HIGH] CWE-924 CVE-2021-34793: A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepo
A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is due to incorrect handling of certai
nvd
CVE-2021-40117HIGHCVSS 7.5≥ 9.9.0, < 9.12.4.26≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-40117 [HIGH] CWE-119 CVE-2021-40117: A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incoming SSL/TLS packets are not properly processed. An at
nvd
CVE-2021-40118HIGHCVSS 7.5≥ 9.9.0, < 9.12.4.29≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-40118 [HIGH] CWE-121 CVE-2021-40118: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd