cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.

Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1

Vulnerabilities

Page 5 of 17
CVE-2026-20100P3HIGHCVSS 7.7v9.12.1v9.12.1.2+145 more2026-03-04
CVE-2026-20100 [HIGH] CWE-120 CVE-2026-20100: A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to cause the device to reload unexpectedly, resulting in a denial of service (DoS) co
nvd
CVE-2010-4675P3CRITICALCVSS 9.0≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2010-4675 [CRITICAL] CWE-264 CVE-2010-4675: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not prop Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, which allows remote authenticated users to bypass intended access restrictions via vectors involving the "lowest security level interface," aka Bug ID CSCsv40504.
nvd
CVE-2022-20742P3HIGHCVSS 7.4fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20742 [HIGH] CWE-325 CVE-2022-20742: A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerability is due to an improper implementation of Galois/Counter Mode (GCM) ciphers. An attacker
nvd
CVE-2019-1706P3HIGHCVSS 8.6≥ 9.9, ≤ 9.9.2.502019-05-03
CVE-2019-1706 [HIGH] CWE-404 CVE-2019-1706: A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance (ASAv) and Firepower 2100 Series running Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device that results in a denial of service (DoS) condition. The vulnerability i
nvd
CVE-2017-6609P3HIGHCVSS 7.7v9.0.1v9.0.2+104 more2017-04-20
CVE-2017-6609 [HIGH] CWE-399 CVE-2017-6609: A vulnerability in the IPsec code of Cisco ASA Software could allow an authenticated, remote attacke A vulnerability in the IPsec code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper parsing of malformed IPsec packets. An attacker could exploit this vulnerability by sending malformed IPsec packets to the affected system. Note: Only traffic directed to the
nvd
CVE-2019-1687P3HIGHCVSS 7.5fixed in 9.4.4.34≥ 9.5, < 9.6.4.25+3 more2019-05-03
CVE-2019-1687 [HIGH] CWE-20 CVE-2019-1687: A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to an error in TCP-based packet inspect
nvd
CVE-2020-3554P3HIGHCVSS 7.5≥ 9.13.0, < 9.13.1.13≥ 9.14.0, < 9.14.1.302020-10-21
CVE-2020-3554 [HIGH] CWE-400 CVE-2020-3554: A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory exhaustion condition. An attacker could exploit this vu
nvd
CVE-2010-4678P3HIGHCVSS 7.5≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2010-4678 [HIGH] CWE-264 CVE-2010-4678: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permit pack Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permit packets to pass before the configuration has been loaded, which might allow remote attackers to bypass intended access restrictions by sending network traffic during device startup, aka Bug ID CSCsy86769.
nvd
CVE-2015-6360P3HIGHCVSS 7.5v8.1.0.104v8.2.0.45+159 more2016-04-21
CVE-2015-6360 [HIGH] CWE-119 CVE-2015-6360: The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a d The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
nvd
CVE-2021-1504P3HIGHCVSS 7.5≥ 9.7, < 9.8.4.35≥ 9.9, < 9.9.2.85+4 more2021-04-29
CVE-2021-1504 [HIGH] CWE-787 CVE-2021-1504: Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat De Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these
nvd
CVE-2021-1445P3HIGHCVSS 7.5≥ 9.7, < 9.8.4.34≥ 9.9, < 9.9.2.85+4 more2021-04-29
CVE-2021-1445 [HIGH] CWE-787 CVE-2021-1445: Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat De Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these
nvd
CVE-2022-20760P3HIGHCVSS 7.5fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20760 [HIGH] CWE-400 CVE-2022-20760: A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to a lack of proper processing of incoming requests. An attacker coul
nvd
CVE-2021-1573P3HIGHCVSS 7.5≥ 9.8, < 9.8.4.40≥ 9.9, < 9.12.4.26+3 more2022-01-11
CVE-2021-1573 [HIGH] CWE-121 CVE-2021-1573: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit t
nvd
CVE-2021-34704P3HIGHCVSS 7.5≥ 9.15, < 9.15.1.17≥ 9.16, < 9.16.22022-01-11
CVE-2021-34704 [HIGH] CWE-121 CVE-2021-34704: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2021-40118P3HIGHCVSS 7.5≥ 9.9.0, < 9.12.4.29≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-40118 [HIGH] CWE-121 CVE-2021-40118: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2026-20049P3HIGHCVSS 7.7≥ 9.18.1, < 9.18.4.66≥ 9.19.1, < 9.20.3.20+2 more2026-03-04
CVE-2026-20049 [HIGH] CWE-131 CVE-2026-20049: A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange versi A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affec
nvd
CVE-2016-6431P3HIGHCVSS 7.5v8.0.2.11v8.0.2.15+204 more2016-10-27
CVE-2016-6431 [HIGH] CWE-20 CVE-2016-6431: A vulnerability in the local Certificate Authority (CA) feature of Cisco ASA Software before 9.6(1.5 A vulnerability in the local Certificate Authority (CA) feature of Cisco ASA Software before 9.6(1.5) could allow an unauthenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper handling of crafted packets during the enrollment operation. An attacker could exploit this vulnerability by sending a crafted
nvd
CVE-2019-1697P3HIGHCVSS 7.5fixed in 9.6.4.25≥ 9.7, < 9.8.4+2 more2019-05-03
CVE-2019-1697 [HIGH] CWE-20 CVE-2019-1697: A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are d
nvd
CVE-2020-3254P3HIGHCVSS 7.5≥ 9.6, < 9.6.4.34≥ 9.8, < 9.8.4.7+3 more2020-05-06
CVE-2020-3254 [HIGH] CWE-400 CVE-2020-3254: Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Ad Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory mana
nvd
CVE-2020-3298P3HIGHCVSS 7.5≥ 9.6.0, ≤ 9.6.4.40≥ 9.8.0, ≤ 9.8.4.17+4 more2020-05-06
CVE-2020-3298 [HIGH] CWE-125 CVE-2020-3298: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memor
nvd