cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

315 known vulnerabilities affecting cisco/adaptive_security_appliance_software.

Total CVEs
315
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
11
Severity breakdown
CRITICAL15HIGH179MEDIUM120LOW1

Vulnerabilities

Page 4 of 16
CVE-2022-20737HIGHCVSS 7.1fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20737 [HIGH] CWE-122 CVE-2022-20737: A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device or to obtain portions of process memory from an affected device. This vu
nvd
CVE-2022-20795HIGHCVSS 7.5≥ 9.17.0, ≤ 9.17.1.92022-04-21
CVE-2022-20795 [HIGH] CWE-345 CVE-2022-20795: A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processi
nvd
CVE-2021-1573HIGHCVSS 7.5≥ 9.8, < 9.8.4.40≥ 9.9, < 9.12.4.26+3 more2022-01-11
CVE-2021-1573 [HIGH] CWE-121 CVE-2021-1573: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit t
nvd
CVE-2021-34704HIGHCVSS 7.5≥ 9.15, < 9.15.1.17≥ 9.16, < 9.16.22022-01-11
CVE-2021-34704 [HIGH] CWE-121 CVE-2021-34704: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2021-34792HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.40≥ 9.12.0, < 9.12.4.29+3 more2021-10-27
CVE-2021-34792 [HIGH] CWE-400 CVE-2021-34792: A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Fir A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacke
nvd
CVE-2021-34783HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.40≥ 9.12.0, < 9.12.4.29+3 more2021-10-27
CVE-2021-34783 [HIGH] CWE-119 CVE-2021-34783: A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance ( A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient validation of SS
nvd
CVE-2021-34793HIGHCVSS 8.6≥ 9.9.0, < 9.12.4.29≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-34793 [HIGH] CWE-924 CVE-2021-34793: A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepo A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is due to incorrect handling of certai
nvd
CVE-2021-40117HIGHCVSS 7.5≥ 9.9.0, < 9.12.4.26≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-40117 [HIGH] CWE-119 CVE-2021-40117: A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incoming SSL/TLS packets are not properly processed. An at
nvd
CVE-2021-40118HIGHCVSS 7.5≥ 9.9.0, < 9.12.4.29≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-40118 [HIGH] CWE-121 CVE-2021-40118: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2021-34791MEDIUMCVSS 5.3≥ 9.12.0, < 9.12.4.18≥ 9.13.0, < 9.14.2.15+1 more2021-10-27
CVE-2021-34791 [MEDIUM] CWE-358 CVE-2021-34791: Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For mo
nvd
CVE-2021-34790MEDIUMCVSS 5.3≥ 9.12.0, < 9.12.4.29≥ 9.13.0, < 9.14.2.15+1 more2021-10-27
CVE-2021-34790 [MEDIUM] CWE-358 CVE-2021-34790: Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For mo
nvd
CVE-2021-40125MEDIUMCVSS 6.5≥ 9.8.0, < 9.8.4.40≥ 9.9.0, < 9.12.4.30+3 more2021-10-27
CVE-2021-40125 [MEDIUM] CWE-416 CVE-2021-40125: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Secu A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. This vulnerability is due to improper control of a reso
nvd
CVE-2021-34787MEDIUMCVSS 5.3≥ 9.9.0, < 9.12.4.25≥ 9.13.0, < 9.14.3.1+2 more2021-10-27
CVE-2021-34787 [MEDIUM] CWE-183 CVE-2021-34787: A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Secu A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices conf
nvd
CVE-2021-34794MEDIUMCVSS 5.3≥ 9.14.0, < 9.14.2.4≥ 9.15.0, < 9.15.1.72021-10-27
CVE-2021-34794 [MEDIUM] CWE-284 CVE-2021-34794: A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control function A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could
nvd
CVE-2021-1422HIGHCVSS 7.7v9.16.12021-07-16
CVE-2021-1422 [HIGH] CWE-617 CVE-2021-1422: A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Softw A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle position to cause an unexpected reload of the device that results in a denial of service (DoS) condit
nvd
CVE-2021-1493HIGHCVSS 7.1≥ 9.8, < 9.8.4.34≥ 9.9, < 9.9.2.85+4 more2021-04-29
CVE-2021-1493 [HIGH] CWE-120 CVE-2021-1493: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to insufficient boundary checks for specific data that is provided to the web services
nvd
CVE-2021-1504HIGHCVSS 7.5≥ 9.7, < 9.8.4.35≥ 9.9, < 9.9.2.85+4 more2021-04-29
CVE-2021-1504 [HIGH] CWE-787 CVE-2021-1504: Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat De Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these
nvd
CVE-2021-1501HIGHCVSS 7.5≥ 9.8, < 9.8.4.34≥ 9.9, < 9.9.2.85+4 more2021-04-29
CVE-2021-1501 [HIGH] CWE-613 CVE-2021-1501: A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition.The vulnerability is due to a crash that occurs during a has
nvd
CVE-2021-1445HIGHCVSS 7.5≥ 9.7, < 9.8.4.34≥ 9.9, < 9.9.2.85+4 more2021-04-29
CVE-2021-1445 [HIGH] CWE-787 CVE-2021-1445: Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat De Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these
nvd
CVE-2021-1488MEDIUMCVSS 6.7≥ 9.13, < 9.13.1.21≥ 9.14, < 9.14.2.13+1 more2021-04-29
CVE-2021-1488 [MEDIUM] CWE-77 CVE-2021-1488: A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS). This vulnerability is due to insufficient input validation. An a
nvd