Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 6 of 17
CVE-2011-3298P3HIGHCVSS 7.9v7.0v7.0\(0\)+69 more2011-10-06
CVE-2011-3298 [HIGH] CWE-287 CVE-2011-3298: Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco C
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.3), 8.0 before 8.0(5.24), 8.1 before 8.1(2.50), 8.2 before 8.2(5), 8.3 before 8.3(2.18), 8.4 before 8.4(1.10), and 8.5 before 8.5(1.1) and Cisco Firewall Services Mo
nvd
CVE-2019-12673P3HIGHCVSS 7.5≥ 9.7, < 9.8.4.10≥ 9.9, < 9.9.2.56+2 more2019-10-02
CVE-2019-12673 [HIGH] CWE-119 CVE-2019-12673: A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Fir
A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of FTP data. An attacker could exploit this vuln
nvd
CVE-2021-34783P3HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.40≥ 9.12.0, < 9.12.4.29+3 more2021-10-27
CVE-2021-34783 [HIGH] CWE-119 CVE-2021-34783: A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (
A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient validation of SS
nvd
CVE-2022-20745P3HIGHCVSS 7.5fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20745 [HIGH] CWE-20 CVE-2022-20745: A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Secur
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS request
nvd
CVE-2010-0440P4MEDIUMCVSS 4.3PoC≥ 8.1, < 8.1\(2.7\)≥ 8.0, < 8.0\(5\)+1 more2010-02-03
CVE-2010-0440 [MEDIUM] CWE-79 CVE-2010-0440: Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, an
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML via a crafted POST parameter, which is not properly handled by an eval statement in binary/mai
nvd
CVE-2025-20127P3HIGHCVSS 7.7v9.20.1v9.20.1.5+8 more2025-08-14
CVE-2025-20127 [HIGH] CWE-404 CVE-2025-20127: A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adapti
A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are associated with incoming TLS 1.3 co
nvd
CVE-2024-20408P3HIGHCVSS 7.7v9.8.1v9.8.1.5+193 more2024-10-23
CVE-2024-20408 [HIGH] CWE-1287 CVE-2024-20408: A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (A
A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need valid remote access VPN user credenti
nvd
CVE-2023-20006P3HIGHCVSS 7.5v9.16.4v9.18.2+1 more2023-06-28
CVE-2023-20006 [HIGH] CWE-681 CVE-2023-20006: A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security
A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do
nvd
CVE-2022-20947P3HIGHCVSS 7.5v9.6.1v9.6.1.3+205 more2022-11-15
CVE-2022-20947 [HIGH] CWE-119 CVE-2022-20947: A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance
A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper processing of HostSc
nvd
CVE-2018-15383P3HIGHCVSS 7.5v9.3v9.4+7 more2018-10-05
CVE-2018-15383 [HIGH] CWE-400 CVE-2018-15383: A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Applianc
A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the af
nvd
CVE-2010-4681P3HIGHCVSS 7.5≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2010-4681 [HIGH] CVE-2010-4681: Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with softw
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to bypass SMTP inspection via vectors involving a prepended space character, aka Bug ID CSCte14901.
nvd
CVE-2019-12698P3HIGHCVSS 7.5≥ 9.7, < 9.8.4.9≥ 9.9, < 9.9.2.56+3 more2019-10-02
CVE-2019-12698 [HIGH] CWE-400 CVE-2019-12698: A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco
A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for a specific WebVPN HTTP page request. An attacker c
nvd
CVE-2020-3195P3HIGHCVSS 7.5≥ 9.12, < 9.12.3.2≥ 9.13, < 9.13.1.72020-05-06
CVE-2020-3195 [HIGH] CWE-400 CVE-2020-3195: A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security App
A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to incorrect processing of certain OSPF packets. An attacker cou
nvd
CVE-2019-12678P3HIGHCVSS 7.5≥ 9.5, < 9.6.4.34≥ 9.7, < 9.8.4.7+3 more2019-10-02
CVE-2019-12678 [HIGH] CWE-191 CVE-2019-12678: A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Securit
A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper parsing of SIP messages
nvd
CVE-2020-3555P3HIGHCVSS 7.5≥ 9.7.0, < 9.8.4.24≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3555 [HIGH] CWE-404 CVE-2020-3555: A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a watchdog timeout and crash d
nvd
CVE-2021-40117P3HIGHCVSS 7.5≥ 9.9.0, < 9.12.4.26≥ 9.13.0, < 9.14.3.9+2 more2021-10-27
CVE-2021-40117 [HIGH] CWE-119 CVE-2021-40117: A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incoming SSL/TLS packets are not properly processed. An at
nvd
CVE-2020-3528P3HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.26≥ 9.9.0, < 9.9.2.80+4 more2020-10-21
CVE-2020-3528 [HIGH] CWE-400 CVE-2020-3528: A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (
A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validatio
nvd
CVE-2022-20795P3HIGHCVSS 7.5≥ 9.17.0, ≤ 9.17.1.92022-04-21
CVE-2022-20795 [HIGH] CWE-345 CVE-2022-20795: A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security
A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processi
nvd
CVE-2011-0394P3HIGHCVSS 7.8≤ 8.3\(1\)v7.0+56 more2011-02-25
CVE-2011-0394 [HIGH] CWE-399 CVE-2011-0394: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5.1), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), 8.2 before 8.2(2.19), and 8.3 before 8.3(1.8); Cisco PIX Security Appliances 500 series devices; and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(20), 3.2 before 3.2(20), 4.
nvd
CVE-2011-0393P3HIGHCVSS 7.8≤ 8.3\(1\)v7.0+56 more2011-02-25
CVE-2011-0393 [HIGH] CWE-399 CVE-2011-0393: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.12), 7.1
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.12), 7.1 and 7.2 before 7.2(5.2), 8.0 before 8.0(5.21), 8.1 before 8.1(2.49), 8.2 before 8.2(3.6), and 8.3 before 8.3(2.7) and Cisco PIX Security Appliances 500 series devices, when transparent firewall mode is configured but IPv6 is not configured, allow remote
nvd