Cisco Asa vulnerabilities
8 known vulnerabilities affecting cisco/asa.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7
Vulnerabilities
Page 1 of 1
CVE-2014-3389P3CRITICALCVSS 9.0v7.2.5v7.2.5.10+24 more2014-10-10
CVE-2014-3389 [CRITICAL] CVE-2014-3389: The VPN implementation in Cisco ASA Software 7.2 before 7.2(5.15), 8.2 before 8.2(5.51), 8.3 before
The VPN implementation in Cisco ASA Software 7.2 before 7.2(5.15), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.15), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), 9.2 before 9.2(2.6), and 9.3 before 9.3(1.1) does not properly implement a tunnel filter, which allows remote authenticated users to obtain failover-unit access
nvd
CVE-2014-3386P3HIGHCVSS 7.8v8.2.5v8.2.5.13+18 more2014-10-10
CVE-2014-3386 [HIGH] CWE-399 CVE-2014-3386: The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4
The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted series of GTP packets, aka Bug ID CSCum56399.
nvd
CVE-2014-3384P3HIGHCVSS 7.8v8.4v8.4.1+8 more2014-10-10
CVE-2014-3384 [HIGH] CWE-399 CVE-2014-3384: The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 befor
The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted packet that is sent during tunnel creation, aka Bug ID CSCum96401.
nvd
CVE-2014-3382P3HIGHCVSS 7.8v7.2.5v7.2.5.10+25 more2014-10-10
CVE-2014-3382 [HIGH] CWE-89 CVE-2014-3382: The SQL*Net inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3
The SQL*Net inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3 before 8.3(2.42), 8.4 before 8.4(7.15), 8.5 before 8.5(1.21), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.5), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via crafted SQL REDIRECT packets, aka
nvd
CVE-2014-3383P3HIGHCVSS 7.8v9.1v9.1.52014-10-10
CVE-2014-3383 [HIGH] CWE-399 CVE-2014-3383: The IKE implementation in the VPN component in Cisco ASA Software 9.1 before 9.1(5.1) allows remote
The IKE implementation in the VPN component in Cisco ASA Software 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via crafted UDP packets, aka Bug ID CSCul36176.
nvd
CVE-2014-3387P3HIGHCVSS 7.8v7.2.5v7.2.5.10+25 more2014-10-10
CVE-2014-3387 [HIGH] CWE-399 CVE-2014-3387: The SunRPC inspection engine in Cisco ASA Software 7.2 before 7.2(5.14), 8.2 before 8.2(5.51), 8.3 b
The SunRPC inspection engine in Cisco ASA Software 7.2 before 7.2(5.14), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.5 before 8.5(1.21), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.5), and 9.1 before 9.1(5.3) allows remote attackers to cause a denial of service (device reload) via crafted SunRPC packets, aka Bug
nvd
CVE-2014-3388P3HIGHCVSS 7.8v9.0v9.1+1 more2014-10-10
CVE-2014-3388 [HIGH] CWE-399 CVE-2014-3388: The DNS inspection engine in Cisco ASA Software 9.0 before 9.0(4.13), 9.1 before 9.1(5.7), and 9.2 b
The DNS inspection engine in Cisco ASA Software 9.0 before 9.0(4.13), 9.1 before 9.1(5.7), and 9.2 before 9.2(2) allows remote attackers to cause a denial of service (device reload) via crafted DNS packets, aka Bug ID CSCuo68327.
nvd
CVE-2014-3385P3HIGHCVSS 7.8v8.3v8.3.2.25+14 more2014-10-10
CVE-2014-3385 [HIGH] CWE-362 CVE-2014-3385: Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software
Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 before 8.5(1.19), 8.6 before 8.6(1.13), 8.7 before 8.7(1.11), 9.0 before 9.0(4.8), and 9.1 before 9.1(4.5) allows remote attackers to cause a denial of service (device reload) via TCP traffic that triggers
nvd