Cisco Asa 5585-X Firmware vulnerabilities

24 known vulnerabilities affecting cisco/asa_5585-x_firmware.

Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH15MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2020-3255HIGHCVSS 7.5v9.10\(1.3\)2020-05-06
CVE-2020-3255 [HIGH] CWE-400 CVE-2020-3255: A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Softw A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a high rate of IPv4
nvd
CVE-2020-3188MEDIUMCVSS 5.3v9.8\(3\)v101.6\(1.96\)2020-05-06
CVE-2020-3188 [MEDIUM] CWE-399 CVE-2020-3188: A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for ma A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition. The vulnerability exists because the default sessi
nvd
CVE-2020-3186MEDIUMCVSS 5.3v9.12\(1.6\)v201.5\(23.16\)2020-05-06
CVE-2020-3186 [MEDIUM] CWE-284 CVE-2020-3186: A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access l
nvd
CVE-2011-2054HIGHCVSS 7.5v8.4\(1\)2020-02-19
CVE-2011-2054 [MEDIUM] CWE-287 CVE-2011-2054: A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate usi A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of certain parameters passed to the af
nvd