Cisco Adaptive Security Appliance Software vulnerabilities
330 known vulnerabilities affecting cisco/adaptive_security_appliance_software.
Total CVEs
330
CISA KEV
12
actively exploited
Public exploits
13
Exploited in wild
18
Severity breakdown
CRITICAL15HIGH185MEDIUM129LOW1
Vulnerabilities
Page 9 of 17
CVE-2018-0229P3MEDIUMCVSS 6.5v9.8\(1.245\)2018-04-19
CVE-2018-0229 [MEDIUM] CWE-384 CVE-2018-0229: A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (S
A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish an aut
nvd
CVE-2019-1945P3HIGHCVSS 7.8fixed in 9.4.4.372019-08-07
CVE-2019-1945 [HIGH] CWE-20 CVE-2019-1945: Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisor
nvd
CVE-2021-1493P3HIGHCVSS 7.1≥ 9.8, < 9.8.4.34≥ 9.9, < 9.9.2.85+4 more2021-04-29
CVE-2021-1493 [HIGH] CWE-120 CVE-2021-1493: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to insufficient boundary checks for specific data that is provided to the web services
nvd
CVE-2024-20358P3MEDIUMCVSS 6.7v9.8.1v9.8.1.5+185 more2024-04-24
CVE-2024-20358 [MEDIUM] CWE-78 CVE-2024-20358: A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is availab
A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. Administrator-level privileges are requ
nvd
CVE-2010-4682P3HIGHCVSS 7.8≤ 8.2\(2\)v7.0+52 more2011-01-07
CVE-2010-4682 [HIGH] CWE-399 CVE-2010-4682: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2
Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (memory consumption) by making multiple incorrect LDAP authentication attempts, aka Bug ID CSCtf29867.
nvd
CVE-2010-4691P3HIGHCVSS 7.8≤ 8.3\(1\)v7.0+56 more2011-01-07
CVE-2010-4691 [HIGH] CVE-2010-4691: Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with softw
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) allows remote attackers to cause a denial of service (device crash) via multicast traffic, aka Bug IDs CSCtg61810 and CSCtg69742.
nvd
CVE-2010-4688P3HIGHCVSS 7.8≤ 8.3\(1\)v7.0+56 more2011-01-07
CVE-2010-4688 [HIGH] CVE-2010-4688: Unspecified vulnerability in the SIP inspection feature on Cisco Adaptive Security Appliances (ASA)
Unspecified vulnerability in the SIP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) allows remote attackers to cause a denial of service (device crash) by making many SIP calls, aka Bug ID CSCte20030.
nvd
CVE-2015-0677P3HIGHCVSS 7.8v8.4.1v8.4.1.3+68 more2015-04-13
CVE-2015-0677 [HIGH] CWE-20 CVE-2015-0677: The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before
The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6), 9.2 before 9.2(3.4), and 9.3 before 9.3(3), when Clientless SSL VPN, AnyConnect SSL VPN, or AnyConnect IKEv2 VPN is used, allows remote attackers to cause a denial of service (VPN outage or device reload)
nvd
CVE-2012-5010P3HIGHCVSS 8.1≤ 8.2\(4\)2017-06-27
CVE-2012-5010 [HIGH] CWE-254 CVE-2012-5010: ASA 5515-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1
ASA 5515-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1 Interim, 9.2.x before 9.2.4 Interim, ASA 5510 Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 8.4.x before 8.4.7 Interim, 8.2.x before 8.2.5 Interim, 9.1.x before 9.1.6 Interim, ASA 5555-X Adaptive Security Appliance ASA for Applic
nvd
CVE-2013-5515P3HIGHCVSS 7.8v8.0v8.0\(2\)+38 more2013-10-13
CVE-2013-5515 [HIGH] CWE-119 CVE-2013-5515: The Clientless SSL VPN feature in Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.
The Clientless SSL VPN feature in Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.7), 8.6.x before 8.6(1.12), 9.0.x before 9.0(2.6), and 9.1.x before 9.1(1.7) allows remote attackers to cause a denial of service (device reload) via crafted HTTPS requests, aka Bug ID CSCua22709.
nvd
CVE-2022-20737P3HIGHCVSS 7.1fixed in 9.12.4.38≥ 9.13.0, < 9.14.4+3 more2022-05-03
CVE-2022-20737 [HIGH] CWE-122 CVE-2022-20737: A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless
A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device or to obtain portions of process memory from an affected device. This vu
nvd
CVE-2016-6461P3MEDIUMCVSS 5.9v9.1\(7\)4v9.1\(7\)7+61 more2016-11-19
CVE-2016-6461 [MEDIUM] CWE-20 CVE-2016-6461: A vulnerability in the HTTP web-based management interface of the Cisco Adaptive Security Appliance
A vulnerability in the HTTP web-based management interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to inject arbitrary XML commands on the affected system. More Information: CSCva38556. Known Affected Releases: 9.1(6.10). Known Fixed Releases: 100.11(0.75) 100.15(0.137) 100.8(40.129) 96.2(0.95) 97.1
nvd
CVE-2010-4672P3HIGHCVSS 7.8≤ 8.2\(3\)v7.0+53 more2011-01-07
CVE-2010-4672 [HIGH] CWE-399 CVE-2010-4672: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier allow
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier allow remote attackers to cause a denial of service (block exhaustion) via EIGRP traffic that triggers an EIGRP multicast storm, aka Bug ID CSCtf20269.
nvd
CVE-2012-2472P3HIGHCVSS 7.8v8.2v8.2\(1\)+15 more2012-08-06
CVE-2012-2472 [HIGH] CWE-399 CVE-2012-2472: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 and 8.4, when SIP ins
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 and 8.4, when SIP inspection is enabled, create many identical pre-allocated secondary pinholes, which might allow remote attackers to cause a denial of service (CPU consumption) via crafted SIP traffic, aka Bug ID CSCtz63143.
nvd
CVE-2013-1152P3HIGHCVSS 7.8v9.02013-04-11
CVE-2013-1152 [HIGH] CVE-2013-1152: Cisco Adaptive Security Appliances (ASA) devices with software 9.0 before 9.0(1.2) allow remote atta
Cisco Adaptive Security Appliances (ASA) devices with software 9.0 before 9.0(1.2) allow remote attackers to cause a denial of service (device reload) via a crafted field in a DNS message, aka Bug ID CSCuc80080.
nvd
CVE-2026-20073P3MEDIUMCVSS 5.8v9.12.1v9.12.1.2+156 more2026-03-04
CVE-2026-20073 [MEDIUM] CWE-284 CVE-2026-20073: A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be denied through an affected device.
This vulnerability is due to improper error handling when an affected device that is joining a c
nvd
CVE-2013-1149P3HIGHCVSS 7.8v7.0v7.0\(0\)+86 more2013-04-11
CVE-2013-1149 [HIGH] CVE-2013-1149: Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(
Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.28), 8.1 and 8.2 before 8.2(5.35), 8.3 before 8.3(2.34), 8.4 before 8.4(4.11), 8.6 before 8.6(1.10), and 8.7 before 8.7(1.3), and Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(24.1) and 4.0 and 4.1 before 4.1(11.1), allow remote attacker
nvd
CVE-2011-4006P3HIGHCVSS 7.8v8.2\(1\)v8.2\(2\)+21 more2012-05-02
CVE-2011-4006 [HIGH] CWE-20 CVE-2011-4006: The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with so
The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.5 allows remote attackers to cause a denial of service (CPU consumption) via an unspecified closing sequence, aka Bug ID CSCtt32565.
nvd
CVE-2005-4499P3HIGHCVSS 7.5v7.0v7.0\(4\)+2 more2005-12-22
CVE-2005-4499 [HIGH] CVE-2005-4499: The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL o
The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS s
nvd
CVE-2018-15399P3MEDIUMCVSS 6.8v9.4\(4\)v9.8\(2\)2018-10-05
CVE-2018-15399 [MEDIUM] CWE-400 CVE-2018-15399: A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cis
A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing boundary check i
nvd