Cisco Adaptive Security Appliance Software vulnerabilities

164 known vulnerabilities affecting cisco/cisco_adaptive_security_appliance_software.

Total CVEs
164
CISA KEV
7
actively exploited
Public exploits
3
Exploited in wild
8
Severity breakdown
CRITICAL5HIGH95MEDIUM63LOW1

Vulnerabilities

Page 2 of 9
CVE-2020-27124HIGHCVSS 8.6vN/A2024-11-18
CVE-2020-27124 [HIGH] CWE-457 CVE-2020-27124: A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software coul A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition. The vulnerability is due to improper error handling on established SSL/TLS connections. An attacker could exploit
cvelistv5nvd
CVE-2021-1444MEDIUMCVSS 6.1v9.4.2.6v9.0.1.1+26 more2024-11-18
CVE-2021-1444 [MEDIUM] CWE-79 CVE-2021-1444: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Softwa A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by
cvelistv5nvd
CVE-2024-20329CRITICALCVSS 9.9v9.17.1v9.17.1.7+25 more2024-10-23
CVE-2024-20329 [CRITICAL] CWE-146 CVE-2024-20329: A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by submitting crafted input when executing remote CLI
cvelistv5nvd
CVE-2024-20268HIGHCVSS 7.7v9.14.1v9.14.1.10+95 more2024-10-23
CVE-2024-20268 [HIGH] CWE-231 CVE-2024-20268: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the device. This vulnerability is due to insufficient input validation of SNMP packets. An attacker
cvelistv5nvd
CVE-2024-20408HIGHCVSS 7.7v9.8.1v9.8.1.5+193 more2024-10-23
CVE-2024-20408 [HIGH] CWE-1287 CVE-2024-20408: A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (A A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need valid remote access VPN user credenti
cvelistv5nvd
CVE-2024-20495HIGHCVSS 8.6v9.8.4.12v9.8.4.15+128 more2024-10-23
CVE-2024-20495 [HIGH] CWE-20 CVE-2024-20495: A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper v
cvelistv5nvd
CVE-2024-20494HIGHCVSS 8.6v9.19.1v9.19.1.5+15 more2024-10-23
CVE-2024-20494 [HIGH] CWE-1287 CVE-2024-20494: A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Sof A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper data validation
cvelistv5nvd
CVE-2024-20426HIGHCVSS 8.6v9.18.1v9.18.1.3+31 more2024-10-23
CVE-2024-20426 [HIGH] CWE-476 CVE-2024-20426: A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient i
cvelistv5nvd
CVE-2024-20260HIGHCVSS 8.6v9.12.3v9.12.1+194 more2024-10-23
CVE-2024-20260 [HIGH] CWE-789 CVE-2024-20260: A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Applian A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL
cvelistv5nvd
CVE-2024-20402HIGHCVSS 8.6v9.8.1v9.8.1.5+193 more2024-10-23
CVE-2024-20402 [HIGH] CWE-788 CVE-2024-20402: A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a logic error in memory manageme
cvelistv5nvd
CVE-2024-20341MEDIUMCVSS 6.1v9.12.3v9.8.3+186 more2024-10-23
CVE-2024-20341 [MEDIUM] CWE-80 CVE-2024-20341: A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) So A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper valida
cvelistv5nvd
CVE-2024-20331MEDIUMCVSS 5.9v9.12.3v9.8.3+186 more2024-10-23
CVE-2024-20331 [MEDIUM] CWE-330 CVE-2024-20331: A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent users from authenticating. This vulnerability is due to insufficient entropy in the authentic
cvelistv5nvd
CVE-2024-20526MEDIUMCVSS 5.3v9.16.4.67v9.16.4.70+2 more2024-10-23
CVE-2024-20526 [MEDIUM] CWE-400 CVE-2024-20526: A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server of an affected device. This vulnerability is due to a logic error when an SSH session is established. An attacker could exploit this vulnerability by sen
cvelistv5nvd
CVE-2024-20384MEDIUMCVSS 5.8v9.16.1v9.16.1.28+70 more2024-10-23
CVE-2024-20384 [MEDIUM] CWE-290 CVE-2024-20384: A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. This vulnerabilit
cvelistv5nvd
CVE-2024-20493MEDIUMCVSS 5.3v9.8.1v9.8.1.5+201 more2024-10-23
CVE-2024-20493 [MEDIUM] CWE-772 CVE-2024-20493: A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Ci A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in a temporary denial of service (
cvelistv5nvd
CVE-2024-20370MEDIUMCVSS 6.0v9.17.1v9.17.1.7+38 more2024-10-23
CVE-2024-20370 [MEDIUM] CWE-264 CVE-2024-20370: A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Secu A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to elevate their administrative privileges to root. The attacker would need valid administrative credentials on the device to
cvelistv5nvd
CVE-2024-20485MEDIUMCVSS 6.7v9.8.1v9.8.1.5+192 more2024-10-23
CVE-2024-20485 [MEDIUM] CWE-94 CVE-2024-20485: A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper v
cvelistv5nvd
CVE-2024-20382MEDIUMCVSS 6.1v9.8.1v9.8.1.5+199 more2024-10-23
CVE-2024-20382 [MEDIUM] CWE-80 CVE-2024-20382: A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) So A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper valida
cvelistv5nvd
CVE-2024-20481MEDIUMCVSS 5.8KEVv9.8.1v9.8.1.5+197 more2024-10-23
CVE-2024-20481 [MEDIUM] CWE-772 CVE-2024-20481: A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnera
cvelistv5nvd
CVE-2024-20299MEDIUMCVSS 5.8v9.12.3v9.8.3+150 more2024-10-23
CVE-2024-20299 [MEDIUM] CWE-290 CVE-2024-20299: A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due
cvelistv5nvd