Cisco Adaptive Security Appliance Software vulnerabilities
315 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
315
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
11
Severity breakdown
CRITICAL15HIGH179MEDIUM120LOW1
Vulnerabilities
Page 6 of 16
CVE-2019-15992HIGHCVSS 7.2≥ 9.7, < 9.8.4.15≥ 9.9, < 9.9.2.61+5 more2020-09-23
CVE-2019-15992 [HIGH] CWE-119 CVE-2019-15992: A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security A
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an affected device. The vulnerability is d
nvd
CVE-2020-3452HIGHCVSS 7.5KEVPoC≥ 9.6, < 9.6.4.42≥ 9.8, < 9.8.4.20+5 more2020-07-22
CVE-2020-3452 [HIGH] CWE-20 CVE-2020-3452: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in H
nvd
CVE-2020-3187CRITICALCVSS 9.1PoC≥ 9.6, < 9.6.4.40≥ 9.8, < 9.8.4.15+4 more2020-05-06
CVE-2020-3187 [CRITICAL] CWE-22 CVE-2020-3187: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of prop
nvd
CVE-2020-3125CRITICALCVSS 9.8≥ 9.8, < 9.8.4.15≥ 9.9, < 9.9.2.66+3 more2020-05-06
CVE-2020-3125 [CRITICAL] CWE-287 CVE-2020-3125: A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) So
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for VPN or local device access. The
nvd
CVE-2020-3195HIGHCVSS 7.5≥ 9.12, < 9.12.3.2≥ 9.13, < 9.13.1.72020-05-06
CVE-2020-3195 [HIGH] CWE-400 CVE-2020-3195: A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security App
A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to incorrect processing of certain OSPF packets. An attacker cou
nvd
CVE-2020-3334HIGHCVSS 7.4≥ 9.10, < 9.10.1.37≥ 9.12, < 9.12.3+1 more2020-05-06
CVE-2020-3334 [HIGH] CWE-399 CVE-2020-3334: A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition on an affected dev
nvd
CVE-2020-3306HIGHCVSS 7.5≥ 9.7, < 9.8.4.10≥ 9.9, < 9.10.1.30+1 more2020-05-06
CVE-2020-3306 [HIGH] CWE-400 CVE-2020-3306: A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir
A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incorrect processing of certain DHCP packets. An attacker could exploit t
nvd
CVE-2020-3303HIGHCVSS 7.5≥ 9.7, < 9.8.4.10≥ 9.9, < 9.10.1.30+1 more2020-05-06
CVE-2020-3303 [HIGH] CWE-399 CVE-2020-3303: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could expl
nvd
CVE-2020-3191HIGHCVSS 8.6≥ 9.6, < 9.6.4.36≥ 9.8, < 9.8.4.12+3 more2020-05-06
CVE-2020-3191 [HIGH] CWE-20 CVE-2020-3191: A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Softw
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper length validation of a field
nvd
CVE-2020-3259HIGHCVSS 7.5KEV≥ 9.8, < 9.8.4.20≥ 9.9, < 9.9.2.67+3 more2020-05-06
CVE-2020-3259 [HIGH] CWE-200 CVE-2020-3259: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer trackin
nvd
CVE-2020-3305HIGHCVSS 7.5≥ 9.7, < 9.8.4.10≥ 9.9, < 9.10.1.30+1 more2020-05-06
CVE-2020-3305 [HIGH] CWE-400 CVE-2020-3305: A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive
A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP packets. An at
nvd
CVE-2020-3254HIGHCVSS 7.5≥ 9.6, < 9.6.4.34≥ 9.8, < 9.8.4.7+3 more2020-05-06
CVE-2020-3254 [HIGH] CWE-400 CVE-2020-3254: Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Ad
Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory mana
nvd
CVE-2020-3298HIGHCVSS 7.5≥ 9.6.0, ≤ 9.6.4.40≥ 9.8.0, ≤ 9.8.4.17+4 more2020-05-06
CVE-2020-3298 [HIGH] CWE-125 CVE-2020-3298: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App
A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memor
nvd
CVE-2020-3196HIGHCVSS 8.6≥ 9.6, < 9.6.4.40≥ 9.8, < 9.8.4.20+4 more2020-05-06
CVE-2020-3196 [HIGH] CWE-400 CVE-2020-3196: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Ad
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of service (DoS) condition. The vulnerabilit
nvd
CVE-2020-3167HIGHCVSS 7.8≥ 9.8, < 9.9.2.66≥ 9.10, < 9.12.3.6+1 more2020-02-26
CVE-2020-3167 [HIGH] CWE-78 CVE-2020-3167: A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an auth
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A
nvd
CVE-2020-3166MEDIUMCVSS 6.7≥ 9.8, < 9.9.2.66≥ 9.10, < 9.13.1.52020-02-26
CVE-2020-3166 [MEDIUM] CWE-20 CVE-2020-3166: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to re
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to a specific CLI command. A successful exploit co
nvd
CVE-2019-12673HIGHCVSS 7.5≥ 9.7, < 9.8.4.10≥ 9.9, < 9.9.2.56+2 more2019-10-02
CVE-2019-12673 [HIGH] CWE-119 CVE-2019-12673: A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Fir
A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of FTP data. An attacker could exploit this vuln
nvd
CVE-2019-15256HIGHCVSS 8.6≥ 9.7, < 9.8.4.10≥ 9.9, < 9.9.2.47+2 more2019-10-02
CVE-2019-15256 [HIGH] CWE-399 CVE-2019-15256: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper ma
nvd
CVE-2019-12678HIGHCVSS 7.5≥ 9.5, < 9.6.4.34≥ 9.7, < 9.8.4.7+3 more2019-10-02
CVE-2019-12678 [HIGH] CWE-191 CVE-2019-12678: A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Securit
A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper parsing of SIP messages
nvd
CVE-2019-12676HIGHCVSS 7.4≥ 9.7, < 9.8.4.8≥ 9.9, < 9.9.2.59+2 more2019-10-02
CVE-2019-12676 [HIGH] CWE-20 CVE-2019-12676: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App
A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the affe
nvd