Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 4 of 17
CVE-2023-20086P3HIGHCVSS 8.6v9.8.1v9.8.1.5+150 more2023-11-01
CVE-2023-20086 [HIGH] CWE-248 CVE-2023-20086: A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco F
A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of ICMPv6 messages. An attacker could exploit this vulnerability by sen
nvd
CVE-2023-20095P3HIGHCVSS 8.6v9.8.1v9.8.1.5+117 more2023-11-01
CVE-2023-20095 [HIGH] CWE-772 CVE-2023-20095: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of HTTPS requests. An attacker could ex
nvd
CVE-2024-20495P3HIGHCVSS 8.6v9.8.4.12v9.8.4.15+128 more2024-10-23
CVE-2024-20495 [HIGH] CWE-20 CVE-2024-20495: A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper v
nvd
CVE-2011-0379P3HIGHCVSS 7.9v1.6.02011-02-25
CVE-2011-0379 [HIGH] CWE-119 CVE-2011-0379: Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x;
Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x; and Cisco TelePresence Manager 1.2.x, 1.3.x, 1.4.x, 1.5.x, and 1.6.2 allows remote at
nvd
CVE-2020-3196P3HIGHCVSS 8.6≥ 9.6, < 9.6.4.40≥ 9.8, < 9.8.4.20+4 more2020-05-06
CVE-2020-3196 [HIGH] CWE-400 CVE-2020-3196: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Ad
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of service (DoS) condition. The vulnerabilit
nvd
CVE-2020-3373P3HIGHCVSS 8.6v9.8.4.22v9.8.4.25+4 more2020-10-21
CVE-2020-3373 [HIGH] CWE-400 CVE-2020-3373: A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA
A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. This memory leak could prevent traffic from being processed through the device, resulting in a denia
nvd
CVE-2021-34793P3HIGHCVSS 8.6≥ 9.9.0, < 9.12.4.29≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-34793 [HIGH] CWE-924 CVE-2021-34793: A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepo
A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is due to incorrect handling of certai
nvd
CVE-2019-1708P3HIGHCVSS 8.6≥ 9.8, ≤ 9.8.4≥ 9.9, ≤ 9.9.2.50+1 more2019-05-03
CVE-2019-1708 [HIGH] CWE-404 CVE-2019-1708: A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) fe
A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (Do
nvd
CVE-2020-3572P3HIGHCVSS 8.6≥ 9.8.0, < 9.8.4.26≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3572 [HIGH] CWE-400 CVE-2020-3572: A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software a
A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak when closing SSL/TLS connections in a specific s
nvd
CVE-2023-20042P3HIGHCVSS 8.6v9.16.1v9.16.1.28+28 more2023-11-01
CVE-2023-20042 [HIGH] CWE-404 CVE-2023-20042: A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Softwar
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handl
nvd
CVE-2026-20014P3HIGHCVSS 7.7≥ 9.12.1, < 9.16.4.85≥ 9.17.1, < 9.18.4.66+3 more2026-03-04
CVE-2026-20014 [HIGH] CWE-401 CVE-2026-20014: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network.
This vulnerability is due to the imp
nvd
CVE-2010-4680P3CRITICALCVSS 9.0≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2010-4680 [CRITICAL] CWE-264 CVE-2010-4680: The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with softw
The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permits the viewing of CIFS shares even when CIFS file browsing has been disabled, which allows remote authenticated users to bypass intended access restrictions via CIFS requests, aka Bug ID CSCsz80777.
nvd
CVE-2017-6610P3HIGHCVSS 7.7v9.0.1v9.0.2+95 more2017-04-20
CVE-2017-6610 [HIGH] CWE-399 CVE-2017-6610: A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software coul
A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of an affected system. The vulnerability is due to insufficient validation of the IKEv1 XAUTH parameters passed during an IKEv1 negotiation. An attacker could exploit this vulnerability by sendin
nvd
CVE-2014-2126P3HIGHCVSS 8.5v8.2v8.4+3 more2014-04-10
CVE-2014-2126 [HIGH] CWE-264 CVE-2014-2126: Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 befo
Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 before 9.0(3.10), and 9.1 before 9.1(3.4) allows remote authenticated users to gain privileges by leveraging level-0 ASDM access, aka Bug ID CSCuj33496.
nvd
CVE-2010-4689P3HIGHCVSS 7.8≤ 8.3\(1\)v7.0+56 more2011-01-07
CVE-2010-4689 [HIGH] CWE-264 CVE-2010-4689: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) do not prop
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) do not properly preserve ACL behavior after a migration, which allows remote attackers to bypass intended access restrictions via an unspecified type of network traffic that had previously been denied, aka Bug ID CSCte46460.
nvd
CVE-2017-6752P3HIGHCVSS 7.5v9.3.3v9.6.22017-08-07
CVE-2017-6752 [HIGH] CWE-200 CVE-2017-6752: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remote attacker to determine valid usernames. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to the interaction between Lightweight Directory Access Protocol
nvd
CVE-2018-0227P3HIGHCVSS 7.5≥ 9.4.4, ≤ 9.4.4.13≥ 9.5.3.7, ≤ 9.5.3.9+6 more2018-04-19
CVE-2018-0227 [HIGH] CWE-295 CVE-2018-0227: A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate A
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification
nvd
CVE-2020-3167P3HIGHCVSS 7.8≥ 9.8, < 9.9.2.66≥ 9.10, < 9.12.3.6+1 more2020-02-26
CVE-2020-3167 [HIGH] CWE-78 CVE-2020-3167: A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an auth
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A
nvd
CVE-2024-20268P3HIGHCVSS 7.7v9.14.1v9.14.1.6+95 more2024-10-23
CVE-2024-20268 [HIGH] CWE-231 CVE-2024-20268: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the device.
This vulnerability is due to insufficient input validation of SNMP packets. An attacker
nvd
CVE-2026-20105P3HIGHCVSS 7.7≥ 9.12.1, < 9.16.4.85≥ 9.17.1, < 9.18.4.66+3 more2026-03-04
CVE-2026-20105 [HIGH] CWE-401 CVE-2026-20105: A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaust device memory resulting in a denial of service (DoS) condition.This does not affect the man
nvd