cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

315 known vulnerabilities affecting cisco/adaptive_security_appliance_software.

Total CVEs
315
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
11
Severity breakdown
CRITICAL15HIGH179MEDIUM120LOW1

Vulnerabilities

Page 5 of 16
CVE-2021-1476MEDIUMCVSS 6.7≥ 9.13, < 9.13.1.21≥ 9.14, < 9.14.2.13+1 more2021-04-29
CVE-2021-1476 [MEDIUM] CWE-78 CVE-2021-1476: A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower T A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient input validation of commands that are supplied
nvd
CVE-2020-3304HIGHCVSS 8.6≥ 9.8.0, < 9.8.4.22≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3304 [HIGH] CWE-400 CVE-2020-3304: A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepow A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP re
nvd
CVE-2020-3529HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.29≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3529 [HIGH] CWE-400 CVE-2020-3529: A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Softw A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to inefficient direct memory access (
nvd
CVE-2020-3572HIGHCVSS 8.6≥ 9.8.0, < 9.8.4.26≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3572 [HIGH] CWE-400 CVE-2020-3572: A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software a A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak when closing SSL/TLS connections in a specific s
nvd
CVE-2020-3555HIGHCVSS 7.5≥ 9.7.0, < 9.8.4.24≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3555 [HIGH] CWE-404 CVE-2020-3555: A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a watchdog timeout and crash d
nvd
CVE-2020-3436HIGHCVSS 8.6≥ 9.8.0, < 9.8.4.25≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3436 [HIGH] CWE-434 CVE-2020-3436: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco F A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload. The vulnerability exists because the affecte
nvd
CVE-2020-3554HIGHCVSS 7.5≥ 9.13.0, < 9.13.1.13≥ 9.14.0, < 9.14.1.302020-10-21
CVE-2020-3554 [HIGH] CWE-400 CVE-2020-3554: A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory exhaustion condition. An attacker could exploit this vu
nvd
CVE-2020-3528HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.26≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3528 [HIGH] CWE-400 CVE-2020-3528: A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance ( A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validatio
nvd
CVE-2020-3373HIGHCVSS 8.6v9.8.4.22v9.8.4.25+4 more2020-10-21
CVE-2020-3373 [HIGH] CWE-400 CVE-2020-3373: A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. This memory leak could prevent traffic from being processed through the device, resulting in a denia
nvd
CVE-2020-3582MEDIUMCVSS 6.1fixed in 9.8.4.26≥ 9.9, < 9.9.2.80+4 more2020-10-21
CVE-2020-3582 [MEDIUM] CWE-79 CVE-2020-3582: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3564MEDIUMCVSS 5.3≥ 9.8.0, < 9.8.4.26≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3564 [MEDIUM] CWE-284 CVE-2020-3564: A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection. The vulnerability is due to ineffective flow tracking of FTP traffic. An attacker could exploit this vulnerability by sending crafte
nvd
CVE-2020-3561MEDIUMCVSS 4.7≥ 9.8.0, < 9.8.4.20≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3561 [MEDIUM] CWE-93 CVE-2020-3561: A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Softwa A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the affected system. The vulnerability is due to improper input sanitization. An attacker could expl
nvd
CVE-2020-3580MEDIUMCVSS 6.1KEVPoCfixed in 9.8.4.34≥ 9.9, < 9.9.2.85+4 more2020-10-21
CVE-2020-3580 [MEDIUM] CWE-79 CVE-2020-3580: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3581MEDIUMCVSS 6.1fixed in 9.8.4.29≥ 9.9, < 9.9.2.80+4 more2020-10-21
CVE-2020-3581 [MEDIUM] CWE-79 CVE-2020-3581: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3457MEDIUMCVSS 6.7≥ 9.8, < 9.8.4.29≥ 9.9, < 9.9.2.80+3 more2020-10-21
CVE-2020-3457 [MEDIUM] CWE-78 CVE-2020-3457: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to in A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted
nvd
CVE-2020-3583MEDIUMCVSS 6.1≥ 9.7, < 9.8.4.29≥ 9.9, < 9.9.2.80+4 more2020-10-21
CVE-2020-3583 [MEDIUM] CWE-79 CVE-2020-3583: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3458MEDIUMCVSS 6.7≥ 9.8.0, < 9.8.4.26≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3458 [MEDIUM] CWE-693 CVE-2020-3458: Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Softw Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass the secure boot mechanism. The vulnerabilities are due to insufficient protections
nvd
CVE-2020-3578MEDIUMCVSS 6.5fixed in 9.6.4.45≥ 9.7, < 9.8.4.26+5 more2020-10-21
CVE-2020-3578 [MEDIUM] CWE-863 CVE-2020-3578: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked. The vulnerability is due to insufficient validation
nvd
CVE-2020-3599MEDIUMCVSS 6.1≥ 9.7.0, < 9.8.4.29≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3599 [MEDIUM] CWE-79 CVE-2020-3599: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Sof A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An
nvd
CVE-2020-3585LOWCVSS 3.7fixed in 9.13.1.13≥ 9.14, < 9.14.1.302020-10-21
CVE-2020-3585 [LOW] CWE-203 CVE-2020-3585: A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper implementation of countermeasures against the Bleic
nvd
Cisco Adaptive Security Appliance Software vulnerabilities | cvebase