cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

315 known vulnerabilities affecting cisco/adaptive_security_appliance_software.

Total CVEs
315
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
11
Severity breakdown
CRITICAL15HIGH179MEDIUM120LOW1

Vulnerabilities

Page 8 of 16
CVE-2018-15454HIGHCVSS 8.6Exploited≥ 9.4, < 9.4.4.27≥ 9.6, < 9.6.4.18+3 more2018-11-01
CVE-2018-15454 [HIGH] CWE-20 CVE-2018-15454: A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Securit A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is
nvd
CVE-2018-15383HIGHCVSS 7.5v9.3v9.4+7 more2018-10-05
CVE-2018-15383 [HIGH] CWE-400 CVE-2018-15383: A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Applianc A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the af
nvd
CVE-2018-15397MEDIUMCVSS 6.8v9.6.4v9.8.2+2 more2018-10-05
CVE-2018-15397 [MEDIUM] CWE-320 CVE-2018-15397: A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) conditio
nvd
CVE-2018-15398MEDIUMCVSS 4.0v9.6\(4.3\)v9.4\(2\)+1 more2018-10-05
CVE-2018-15398 [MEDIUM] CWE-284 CVE-2018-15398: A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an affected device. The vulnerability is due to errors that could occur wh
nvd
CVE-2018-15399MEDIUMCVSS 6.8v9.4\(4\)v9.8\(2\)2018-10-05
CVE-2018-15399 [MEDIUM] CWE-400 CVE-2018-15399: A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cis A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing boundary check i
nvd
CVE-2018-0296HIGHCVSS 7.5KEVPoC≥ 9.1, < 9.1.7.29≥ 9.2, < 9.2.4.33+5 more2018-06-07
CVE-2018-0296 [HIGH] CWE-20 CVE-2018-0296: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an u A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system
nvd
CVE-2018-0230HIGHCVSS 8.6v9.8\(2\)2018-04-19
CVE-2018-0230 [HIGH] CWE-400 CVE-2018-0230: A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (F A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to the affe
nvd
CVE-2018-0231HIGHCVSS 8.6v9.8\(1\)v98.1\(1.154\)2018-04-19
CVE-2018-0231 [HIGH] CWE-20 CVE-2018-0231: A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance ( A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validatio
nvd
CVE-2018-0228HIGHCVSS 8.6≥ 9.1, < 9.1.7.20≥ 9.3, < 9.4.4.13+6 more2018-04-19
CVE-2018-0228 [HIGH] CWE-20 CVE-2018-0228: A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incorrect handling of an internal software lock that
nvd
CVE-2018-0240HIGHCVSS 8.6≥ 9.6.0.0, < 9.6.4.6≥ 9.7.0.0, < 9.7.1.24+2 more2018-04-19
CVE-2018-0240 [HIGH] CWE-399 CVE-2018-0240: Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Secu Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to log
nvd
CVE-2018-0227HIGHCVSS 7.5≥ 9.4.4, ≤ 9.4.4.13≥ 9.5.3.7, ≤ 9.5.3.9+6 more2018-04-19
CVE-2018-0227 [HIGH] CWE-295 CVE-2018-0227: A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate A A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification
nvd
CVE-2018-0251MEDIUMCVSS 6.1v9.8\(2.15\)v9.9\(1\)2018-04-19
CVE-2018-0251 [MEDIUM] CWE-79 CVE-2018-0251: A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets La A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of that portal on an affected device. The vulnerability is due to insuf
nvd
CVE-2018-0242MEDIUMCVSS 6.1v9.1\(7.245\)v9.6\(3\)+2 more2018-04-19
CVE-2018-0242 [MEDIUM] CWE-79 CVE-2018-0242: A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance co A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web
nvd
CVE-2018-0229MEDIUMCVSS 6.5v9.8\(1.245\)2018-04-19
CVE-2018-0229 [MEDIUM] CWE-384 CVE-2018-0229: A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (S A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish an aut
nvd
CVE-2018-0101CRITICALCVSS 10.0PoCfixed in 9.1.7.23≥ 9.2.0, < 9.2.4.27+5 more2018-01-29
CVE-2018-0101 [CRITICAL] CWE-415 CVE-2018-0101: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security A A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled o
nvd
CVE-2017-12246HIGHCVSS 8.6v9.4\(3\)v9.7\(1\)+1 more2017-10-05
CVE-2017-12246 [HIGH] CWE-399 CVE-2017-12246: A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Securit A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of the HTTP header.
nvd
CVE-2017-6752HIGHCVSS 7.5v9.3.3v9.6.22017-08-07
CVE-2017-6752 [HIGH] CWE-200 CVE-2017-6752: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2 A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remote attacker to determine valid usernames. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to the interaction between Lightweight Directory Access Protocol
nvd
CVE-2017-6765MEDIUMCVSS 6.1v9.1\(6.11\)v9.4\(1.2\)2017-08-07
CVE-2017-6765 [MEDIUM] CWE-79 CVE-2017-6765: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.1 A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.1(6.11) and 9.4(1.2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka WebVPN XSS. The vulnerability is due to insufficient valida
nvd
CVE-2017-6770MEDIUMCVSS 4.2v7.0.1v7.0.1.4+345 more2017-08-07
CVE-2017-6770 [MEDIUM] CWE-20 CVE-2017-6770: Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an unauthenticated, remote attacker to t
nvd
CVE-2017-6764MEDIUMCVSS 5.4v9.5\(1\)2017-08-07
CVE-2017-6764 [MEDIUM] CWE-79 CVE-2017-6764: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5 A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the
nvd