cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

162 known vulnerabilities affecting cisco/cisco_adaptive_security_appliance_software.

Total CVEs
162
CISA KEV
7
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL5HIGH94MEDIUM62LOW1

Vulnerabilities

Page 4 of 9
CVE-2022-20742P3HIGHCVSS 7.4vn/a2022-05-03
CVE-2022-20742 [HIGH] CWE-325 CVE-2022-20742: A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerability is due to an improper implementation of Galois/Counter Mode (GCM) ciphers. An attacker
nvd
CVE-2019-1706P3HIGHCVSS 8.6≥ unspecified, < 9.9.2.502019-05-03
CVE-2019-1706 [HIGH] CWE-404 CVE-2019-1706: A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance (ASAv) and Firepower 2100 Series running Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device that results in a denial of service (DoS) condition. The vulnerability i
nvd
CVE-2019-1687P3HIGHCVSS 7.5≥ unspecified, < 9.4.4.34≥ unspecified, < 9.8.4+1 more2019-05-03
CVE-2019-1687 [HIGH] CWE-20 CVE-2019-1687: A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to an error in TCP-based packet inspect
nvd
CVE-2020-3554P3HIGHCVSS 7.5vn/a2020-10-21
CVE-2020-3554 [HIGH] CWE-400 CVE-2020-3554: A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory exhaustion condition. An attacker could exploit this vu
nvd
CVE-2021-1504P3HIGHCVSS 7.5vn/a2021-04-29
CVE-2021-1504 [HIGH] CWE-787 CVE-2021-1504: Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat De Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these
nvd
CVE-2021-1445P3HIGHCVSS 7.5vn/a2021-04-29
CVE-2021-1445 [HIGH] CWE-787 CVE-2021-1445: Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat De Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these
nvd
CVE-2022-20760P3HIGHCVSS 7.5vn/a2022-05-03
CVE-2022-20760 [HIGH] CWE-400 CVE-2022-20760: A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to a lack of proper processing of incoming requests. An attacker coul
nvd
CVE-2021-1573P3HIGHCVSS 7.5≥ unspecified, < 6.4.0.132022-01-11
CVE-2021-1573 [HIGH] CWE-121 CVE-2021-1573: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit t
nvd
CVE-2021-34704P3HIGHCVSS 7.5≥ unspecified, < 6.4.0.132022-01-11
CVE-2021-34704 [HIGH] CWE-121 CVE-2021-34704: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2021-40118P3HIGHCVSS 7.5vn/a2021-10-27
CVE-2021-40118 [HIGH] CWE-121 CVE-2021-40118: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2019-1697P3HIGHCVSS 7.5≥ unspecified, < 9.6(4.21)2019-05-03
CVE-2019-1697 [HIGH] CWE-20 CVE-2019-1697: A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are d
nvd
CVE-2020-3254P3HIGHCVSS 7.5vn/a2020-05-06
CVE-2020-3254 [HIGH] CWE-400 CVE-2020-3254: Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Ad Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory mana
nvd
CVE-2020-3298P3HIGHCVSS 7.5vn/a2020-05-06
CVE-2020-3298 [HIGH] CWE-125 CVE-2020-3298: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memor
nvd
CVE-2019-12673P3HIGHCVSS 7.5≥ unspecified, < n/a2019-10-02
CVE-2019-12673 [HIGH] CWE-119 CVE-2019-12673: A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Fir A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of FTP data. An attacker could exploit this vuln
nvd
CVE-2021-34783P3HIGHCVSS 7.5vn/a2021-10-27
CVE-2021-34783 [HIGH] CWE-119 CVE-2021-34783: A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance ( A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient validation of SS
nvd
CVE-2022-20745P3HIGHCVSS 7.5vn/a2022-05-03
CVE-2022-20745 [HIGH] CWE-20 CVE-2022-20745: A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Secur A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS request
nvd
CVE-2025-20127P3HIGHCVSS 7.7v9.20.1v9.20.1.5+8 more2025-08-14
CVE-2025-20127 [HIGH] CWE-404 CVE-2025-20127: A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adapti A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are associated with incoming TLS 1.3 co
nvd
CVE-2025-20244P3HIGHCVSS 7.7v9.12.3v9.8.3+203 more2025-08-14
CVE-2025-20244 [HIGH] CWE-1287 CVE-2025-20244: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security App A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker that is authenticated as a VPN user to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerab
nvd
CVE-2024-20408P3HIGHCVSS 7.7v9.8.1v9.8.1.5+193 more2024-10-23
CVE-2024-20408 [HIGH] CWE-1287 CVE-2024-20408: A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (A A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need valid remote access VPN user credenti
nvd
CVE-2023-20006P3HIGHCVSS 7.5v9.16.4v9.18.2+1 more2023-06-28
CVE-2023-20006 [HIGH] CWE-681 CVE-2023-20006: A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do
nvd
Cisco Adaptive Security Appliance Software vulnerabilities | cvebase