Cisco Adaptive Security Appliance Software vulnerabilities
162 known vulnerabilities affecting cisco/cisco_adaptive_security_appliance_software.
Total CVEs
162
CISA KEV
7
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL5HIGH94MEDIUM62LOW1
Vulnerabilities
Page 3 of 9
CVE-2020-3191P3HIGHCVSS 8.6vn/a2020-05-06
CVE-2020-3191 [HIGH] CWE-20 CVE-2020-3191: A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Softw
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper length validation of a field
nvd
CVE-2019-1713P3HIGHCVSS 8.8≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+3 more2019-05-03
CVE-2019-1713 [HIGH] CWE-352 CVE-2019-1713: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Sof
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An a
nvd
CVE-2020-27124P3HIGHCVSS 8.6vN/A2024-11-18
CVE-2020-27124 [HIGH] CWE-457 CVE-2020-27124: A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software coul
A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition.
The vulnerability is due to improper error handling on established SSL/TLS connections. An attacker could exploit
nvd
CVE-2023-20086P3HIGHCVSS 8.6v9.8.1v9.8.1.5+149 more2023-11-01
CVE-2023-20086 [HIGH] CWE-248 CVE-2023-20086: A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco F
A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of ICMPv6 messages. An attacker could exploit this vulnerability by sen
nvd
CVE-2023-20095P3HIGHCVSS 8.6v9.8.1v9.8.1.5+120 more2023-11-01
CVE-2023-20095 [HIGH] CWE-772 CVE-2023-20095: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of HTTPS requests. An attacker could ex
nvd
CVE-2024-20495P3HIGHCVSS 8.6v9.8.4.12v9.8.4.15+128 more2024-10-23
CVE-2024-20495 [HIGH] CWE-20 CVE-2024-20495: A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper v
nvd
CVE-2019-1873P3HIGHCVSS 8.6≥ unspecified, < 9.4.4.36≥ unspecified, < 9.6.4.29+4 more2019-07-10
CVE-2019-1873 [HIGH] CWE-400 CVE-2019-1873: A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and
A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vulnerability is due to incomplete input validation of a Secure Sockets Layer (SSL) or Transport Layer Security (TLS)
nvd
CVE-2020-3196P3HIGHCVSS 8.6vn/a2020-05-06
CVE-2020-3196 [HIGH] CWE-400 CVE-2020-3196: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Ad
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of service (DoS) condition. The vulnerabilit
nvd
CVE-2020-3373P3HIGHCVSS 8.6vn/a2020-10-21
CVE-2020-3373 [HIGH] CWE-400 CVE-2020-3373: A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA
A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. This memory leak could prevent traffic from being processed through the device, resulting in a denia
nvd
CVE-2020-3456P3HIGHCVSS 8.8vn/a2020-10-21
CVE-2020-3456 [HIGH] CWE-352 CVE-2020-3456: A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an u
A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by pe
nvd
CVE-2021-34793P3HIGHCVSS 8.6vn/a2021-10-27
CVE-2021-34793 [HIGH] CWE-924 CVE-2021-34793: A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepo
A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is due to incorrect handling of certai
nvd
CVE-2024-20260P3HIGHCVSS 8.6v9.12.3v9.12.1+194 more2024-10-23
CVE-2024-20260 [HIGH] CWE-789 CVE-2024-20260: A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Applian
A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL
nvd
CVE-2019-1708P3HIGHCVSS 8.6≥ unspecified, < 9.8.4≥ unspecified, < 9.9.2.50+1 more2019-05-03
CVE-2019-1708 [HIGH] CWE-404 CVE-2019-1708: A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) fe
A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (Do
nvd
CVE-2020-3572P3HIGHCVSS 8.6vn/a2020-10-21
CVE-2020-3572 [HIGH] CWE-400 CVE-2020-3572: A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software a
A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak when closing SSL/TLS connections in a specific s
nvd
CVE-2023-20042P3HIGHCVSS 8.6v9.16.1v9.16.1.28+28 more2023-11-01
CVE-2023-20042 [HIGH] CWE-404 CVE-2023-20042: A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Softwar
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handl
nvd
CVE-2019-1715P3HIGHCVSS 7.5≥ unspecified, < 9.8.4≥ unspecified, < 9.9.2.502019-05-03
CVE-2019-1715 [HIGH] CWE-332 CVE-2019-1715: A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private k
nvd
CVE-2023-20107P3HIGHCVSS 7.5vn/a2023-03-23
CVE-2023-20107 [HIGH] CWE-332 CVE-2023-20107: A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number
A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote attacker to cause a cryptographic co
nvd
CVE-2020-3167P3HIGHCVSS 7.8≥ unspecified, < n/a2020-02-26
CVE-2020-3167 [HIGH] CWE-78 CVE-2020-3167: A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an auth
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A
nvd
CVE-2020-3171P3HIGHCVSS 7.8≥ unspecified, < n/a2020-02-26
CVE-2020-3171 [HIGH] CWE-78 CVE-2020-3171: A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manage
A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by
nvd
CVE-2024-20268P3HIGHCVSS 7.7v9.14.1v9.14.1.10+95 more2024-10-23
CVE-2024-20268 [HIGH] CWE-231 CVE-2024-20268: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the device.
This vulnerability is due to insufficient input validation of SNMP packets. An attacker
nvd