cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

162 known vulnerabilities affecting cisco/cisco_adaptive_security_appliance_software.

Total CVEs
162
CISA KEV
7
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL5HIGH94MEDIUM62LOW1

Vulnerabilities

Page 2 of 9
CVE-2019-1714P3HIGHCVSS 8.6≥ unspecified, < 9.8.4≥ unspecified, < 9.9.2.50+1 more2019-05-03
CVE-2019-1714 [HIGH] CWE-255 CVE-2019-1714: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-O A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN
nvd
CVE-2025-20251P3HIGHCVSS 8.5v9.12.3v9.8.3+218 more2025-08-14
CVE-2025-20251 [HIGH] CWE-1287 CVE-2025-20251: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security App A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system files are manipulated, new Remote Acc
nvd
CVE-2025-20253P3HIGHCVSS 8.6v9.12.3v9.8.3+215 more2025-08-14
CVE-2025-20253 [HIGH] CWE-835 CVE-2025-20253: A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Sof A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is due to the improper processing of IKEv2 packets. An attacker could exploit this vulnerabil
nvd
CVE-2020-3304P3HIGHCVSS 8.6vn/a2020-10-21
CVE-2020-3304 [HIGH] CWE-400 CVE-2020-3304: A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepow A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP re
nvd
CVE-2018-15465P3HIGHCVSS 8.1vn/a2018-12-24
CVE-2018-15465 [HIGH] CWE-285 CVE-2018-15465: A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software c A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interfa
nvd
CVE-2025-20263P3HIGHCVSS 8.6v9.12.3v9.8.3+212 more2025-08-14
CVE-2025-20263 [HIGH] CWE-680 CVE-2025-20263: A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance ( A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. This vulnerability is due to insufficient boundary checks for specific data that is
nvd
CVE-2019-15992P3HIGHCVSS 7.2vn/a2020-09-23
CVE-2019-15992 [HIGH] CWE-119 CVE-2019-15992: A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security A A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an affected device. The vulnerability is d
nvd
CVE-2025-20136P3HIGHCVSS 8.6v9.12.3v9.8.3+207 more2025-08-14
CVE-2025-20136 [HIGH] CWE-835 CVE-2025-20136: A vulnerability in the function that performs IPv4 and IPv6 Network Address Translation (NAT) DNS in A vulnerability in the function that performs IPv4 and IPv6 Network Address Translation (NAT) DNS inspection for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of se
nvd
CVE-2025-20239P3HIGHCVSS 8.6v9.8.1v9.8.1.5+218 more2025-08-14
CVE-2025-20239 [HIGH] CWE-401 CVE-2025-20239: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This vul
nvd
CVE-2020-3436P3HIGHCVSS 8.6vn/a2020-10-21
CVE-2020-3436 [HIGH] CWE-434 CVE-2020-3436: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco F A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload. The vulnerability exists because the affecte
nvd
CVE-2025-20134P3HIGHCVSS 8.6v9.12.4.39v9.12.4.40+22 more2025-08-14
CVE-2025-20134 [HIGH] CWE-415 CVE-2025-20134: A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance ( A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper pa
nvd
CVE-2022-20715P3HIGHCVSS 8.6vn/a2022-05-03
CVE-2022-20715 [HIGH] CWE-399 CVE-2022-20715: A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Sof A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation of errors that are logged as a r
nvd
CVE-2024-20426P3HIGHCVSS 8.6v9.18.1v9.18.1.3+31 more2024-10-23
CVE-2024-20426 [HIGH] CWE-476 CVE-2024-20426: A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient i
nvd
CVE-2024-20402P3HIGHCVSS 8.6v9.8.1v9.8.1.5+193 more2024-10-23
CVE-2024-20402 [HIGH] CWE-788 CVE-2024-20402: A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a logic error in memory manageme
nvd
CVE-2024-20494P3HIGHCVSS 8.6v9.19.1v9.19.1.5+15 more2024-10-23
CVE-2024-20494 [HIGH] CWE-1287 CVE-2024-20494: A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Sof A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper data validation
nvd
CVE-2025-20182P3HIGHCVSS 8.6v9.12.3v9.8.3+191 more2025-05-07
CVE-2025-20182 [HIGH] CWE-787 CVE-2025-20182: A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vu
nvd
CVE-2022-20829P3HIGHCVSS 7.2vn/a2022-06-24
CVE-2022-20829 [HIGH] CWE-345 CVE-2022-20829: A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the val A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrative privileges to upload an ASDM image that contains malicious code to a device that is running Cisco ASA Software.
nvd
CVE-2019-1694P3HIGHCVSS 8.6≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+3 more2019-05-03
CVE-2019-1694 [HIGH] CWE-20 CVE-2019-1694: A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper handling of TCP traffic. An att
nvd
CVE-2019-15256P3HIGHCVSS 8.6≥ unspecified, < n/a2019-10-02
CVE-2019-15256 [HIGH] CWE-399 CVE-2019-15256: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper ma
nvd
CVE-2018-15388P3HIGHCVSS 8.6≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+2 more2019-05-03
CVE-2018-15388 [HIGH] CWE-400 CVE-2018-15388: A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for existing WebVPN login operations. An attacke
nvd
Cisco Adaptive Security Appliance Software vulnerabilities | cvebase