Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 7 of 17
CVE-2011-0396P3HIGHCVSS 7.8v8.0v8.3\(1\)2011-02-25
CVE-2011-0396 [HIGH] CWE-264 CVE-2011-0396: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCtk12352.
nvd
CVE-2021-1422P3HIGHCVSS 7.7v9.16.12021-07-16
CVE-2021-1422 [HIGH] CWE-617 CVE-2021-1422: A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Softw
A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle position to cause an unexpected reload of the device that results in a denial of service (DoS) condit
nvd
CVE-2021-34792P3HIGHCVSS 7.5≥ 9.8.0, < 9.8.4.40≥ 9.12.0, < 9.12.4.29+3 more2021-10-27
CVE-2021-34792 [HIGH] CWE-400 CVE-2021-34792: A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Fir
A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacke
nvd
CVE-2021-1501P3HIGHCVSS 7.5≥ 9.8, < 9.8.4.34≥ 9.9, < 9.9.2.85+4 more2021-04-29
CVE-2021-1501 [HIGH] CWE-613 CVE-2021-1501: A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition.The vulnerability is due to a crash that occurs during a has
nvd
CVE-2020-3306P3HIGHCVSS 7.5≥ 9.7, < 9.8.4.10≥ 9.9, < 9.10.1.30+1 more2020-05-06
CVE-2020-3306 [HIGH] CWE-400 CVE-2020-3306: A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir
A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incorrect processing of certain DHCP packets. An attacker could exploit t
nvd
CVE-2020-3305P3HIGHCVSS 7.5≥ 9.7, < 9.8.4.10≥ 9.9, < 9.10.1.30+1 more2020-05-06
CVE-2020-3305 [HIGH] CWE-400 CVE-2020-3305: A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive
A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP packets. An at
nvd
CVE-2011-0395P3HIGHCVSS 7.8v8.0v8.3\(1\)2011-02-25
CVE-2011-0395 [HIGH] CWE-399 CVE-2011-0395: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1 before 8.1(2.48), 8.2 before 8.2(3), and 8.3 before 8.3(2.1), when the RIP protocol and the Cisco Phone Proxy functionality are configured, allow remote attackers to cause a denial of service (device reload) via a RIP update, aka Bug ID CSCtg66583.
nvd
CVE-2015-6327P3HIGHCVSS 7.8v7.2.1v7.2.1.9+172 more2015-10-25
CVE-2015-6327 [HIGH] CWE-399 CVE-2015-6327: The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(
The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.8), 9.2 before 9.2(4), and 9.3 before 9.3(3) allows remote attackers to cause a denial of service (device reload) via crafted ISAKMP UDP packets,
nvd
CVE-2012-0356P3HIGHCVSS 7.8v7.0v7.0\(0\)+83 more2012-03-15
CVE-2012-0356 [HIGH] CWE-20 CVE-2012-0356: Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 through 7.2 before 7.2(5.7), 8.0 before 8.0(5.27), 8.1 before 8.1(2.53), 8.2 before 8.2(5.8), 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.2) and the Firewall Services Module (FWSM)
nvd
CVE-2012-4660P3HIGHCVSS 7.8v8.2v8.2\(1\)+18 more2012-10-29
CVE-2012-4660 [HIGH] CWE-119 CVE-2012-4660: The SIP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the A
The SIP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.17), 8.3 before 8.3(2.28), 8.4 before 8.4(2.13), 8.5 before 8.5(1.4), and 8.6 before 8.6(1.5) allows remote attackers to cause a denial of service (device rel
nvd
CVE-2011-3303P3HIGHCVSS 7.8v7.0v7.0\(0\)+69 more2011-10-06
CVE-2011-3303 [HIGH] CWE-399 CVE-2011-3303: Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco C
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.4), 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.6), 8.3 before 8.3(2.23), 8.4 before 8.4(2.7), and 8.5 before 8.5(1.1) and Cisco Firewall Services M
nvd
CVE-2020-3303P3HIGHCVSS 7.5≥ 9.7, < 9.8.4.10≥ 9.9, < 9.10.1.30+1 more2020-05-06
CVE-2020-3303 [HIGH] CWE-399 CVE-2020-3303: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could expl
nvd
CVE-2013-5542P3HIGHCVSS 8.5v9.0v9.0\(1\)+18 more2013-10-21
CVE-2013-5542 [HIGH] CWE-399 CVE-2013-5542: Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.2), 8.7 before 8.7(1.8), 9.0 befor
Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.2), 8.7 before 8.7(1.8), 9.0 before 9.0(3.6), and 9.1 before 9.1(2.8) allows remote attackers to cause a denial of service (firewall-session disruption or device reload) via crafted ICMP packets, aka Bug ID CSCui77398.
nvd
CVE-2026-20016P3MEDIUMCVSS 6.7≥ 9.12.1, < 9.16.4.85≥ 9.17.1, < 9.18.4.66+3 more2026-03-04
CVE-2026-20016 [MEDIUM] CWE-88 CVE-2026-20016: A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Se
A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the attacker must have valid administrative credentials on an aff
nvd
CVE-2010-4670P3HIGHCVSS 7.8≤ 8.2\(3\)v7.0+53 more2011-01-07
CVE-2010-4670 [HIGH] CWE-399 CVE-2010-4670: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack on Cisco Adaptive Security App
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier, and Cisco PIX Security Appliances devices, allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with d
nvd
CVE-2014-3392P3HIGHCVSS 8.3v8.2v8.2.0.45+103 more2014-10-10
CVE-2014-3392 [HIGH] CVE-2014-3392: The Clientless SSL VPN portal in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4
The Clientless SSL VPN portal in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.15), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), 9.2 before 9.2(2.8), and 9.3 before 9.3(1.1) allows remote attackers to obtain sensitive information from process memory or modify memory contents via crafted parameters, aka Bug I
nvd
CVE-2012-0355P3HIGHCVSS 7.8v8.4v8.4\(1\)+6 more2012-03-15
CVE-2012-0355 [HIGH] CWE-20 CVE-2012-0355: Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(2.11) and 8.5 before 8.5(1.4) allow remote attackers to cause a denial of service (device reload) via (1) IPv4 or (2) IPv6 packets that trigger syslog message 305006, aka Bug ID CSCts39634.
nvd
CVE-2011-3304P3HIGHCVSS 7.8v7.0v7.0\(0\)+69 more2011-10-06
CVE-2011-3304 [HIGH] CWE-399 CVE-2011-3304: Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco C
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.2 before 7.2(5.3), 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.11), 8.3 before 8.3(2.23), 8.4 before 8.4(2), and 8.5 before 8.5(1.1) allow remote attackers to cause a denial of service (device
nvd
CVE-2015-0675P3HIGHCVSS 8.3v9.1.1v9.1.1.4+21 more2015-04-13
CVE-2015-0675 [HIGH] CWE-284 CVE-2015-0675: The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1
The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate failover communication messages, which allows remote attackers to reconfigure an ASA device, and consequently obtain administrative control, by sending crafted UDP packets over the
nvd
CVE-2012-3058P3HIGHCVSS 7.8v8.4v8.4\(1\)+7 more2012-06-20
CVE-2012-3058 [HIGH] CVE-2012-3058: Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(4.1), 8.5 before 8.5(1.11), and 8.6 before 8.6(1.3) allow remote attackers to cause a denial of service (device reload) via IPv6 transit traffic that triggers syslog message 110003, aka Bug ID CSCu
nvd