cbcvebase.

Cisco Adaptive Security Appliance Software vulnerabilities

162 known vulnerabilities affecting cisco/cisco_adaptive_security_appliance_software.

Total CVEs
162
CISA KEV
7
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL5HIGH94MEDIUM62LOW1

Vulnerabilities

Page 7 of 9
CVE-2024-20293P4MEDIUMCVSS 5.8v9.19.1v9.19.1.5+7 more2024-05-22
CVE-2024-20293 [MEDIUM] CWE-436 CVE-2024-20293: A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Applian A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to a logic error that occ
nvd
CVE-2018-15397P4MEDIUMCVSS 6.8vn/a2018-10-05
CVE-2018-15397 [MEDIUM] CWE-320 CVE-2018-15397: A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) conditio
nvd
CVE-2019-12677P4MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-02
CVE-2019-12677 [MEDIUM] CWE-172 CVE-2019-12677: A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance ( A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition that prevents the creation of new SSL/Transport Layer Security (TLS) connections to an affected device. The vulnerability is due to incorrect hand
nvd
CVE-2025-20225P4MEDIUMCVSS 5.8v9.8.1v9.8.1.5+218 more2025-08-14
CVE-2025-20225 [MEDIUM] CWE-401 CVE-2025-20225: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This v
nvd
CVE-2025-20224P4MEDIUMCVSS 5.8v9.8.1v9.8.1.5+218 more2025-08-14
CVE-2025-20224 [MEDIUM] CWE-401 CVE-2025-20224: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adapt A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This vulnerability is due to improper p
nvd
CVE-2022-20826P4MEDIUMCVSS 6.8v9.17.1v9.17.1.9+4 more2022-11-15
CVE-2022-20826 [MEDIUM] CWE-501 CVE-2022-20826: A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are run A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This vulnerability is due to a l
nvd
CVE-2021-1488P4MEDIUMCVSS 6.7vn/a2021-04-29
CVE-2021-1488 [MEDIUM] CWE-77 CVE-2021-1488: A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS). This vulnerability is due to insufficient input validation. An a
nvd
CVE-2019-1695P4MEDIUMCVSS 6.5≥ unspecified, < 9.8.4≥ unspecified, < 9.9.2.50+1 more2019-05-03
CVE-2019-1695 [MEDIUM] CWE-284 CVE-2019-1695: A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected d
nvd
CVE-2025-20254P4MEDIUMCVSS 5.8v9.12.1v9.12.1.2+168 more2025-08-14
CVE-2025-20254 [MEDIUM] CWE-401 CVE-2025-20254: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adapt A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This vulnerability is due to improper p
nvd
CVE-2025-20252P4MEDIUMCVSS 5.8v9.8.4.15v9.8.4.17+178 more2025-08-14
CVE-2025-20252 [MEDIUM] CWE-401 CVE-2025-20252: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adapt A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This vulnerability is due to improper p
nvd
CVE-2020-3564P4MEDIUMCVSS 5.3vn/a2020-10-21
CVE-2020-3564 [MEDIUM] CWE-284 CVE-2020-3564: A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection. The vulnerability is due to ineffective flow tracking of FTP traffic. An attacker could exploit this vulnerability by sending crafte
nvd
CVE-2025-20219P4MEDIUMCVSS 5.3v9.18.2v9.18.2.5+42 more2025-08-14
CVE-2025-20219 [MEDIUM] CWE-284 CVE-2025-20219: A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secur A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should have been blocked to a loopback interface. This vulnerability is
nvd
CVE-2020-3458P4MEDIUMCVSS 6.7vn/a2020-10-21
CVE-2020-3458 [MEDIUM] CWE-693 CVE-2020-3458: Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Softw Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass the secure boot mechanism. The vulnerabilities are due to insufficient protections
nvd
CVE-2019-1705P4MEDIUMCVSS 5.9≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+3 more2019-05-03
CVE-2019-1705 [MEDIUM] CWE-404 CVE-2019-1705: A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulner
nvd
CVE-2024-20341P4MEDIUMCVSS 6.1v9.12.3v9.8.3+186 more2024-10-23
CVE-2024-20341 [MEDIUM] CWE-80 CVE-2024-20341: A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) So A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper valida
nvd
CVE-2024-20382P4MEDIUMCVSS 6.1v9.8.1v9.8.1.5+199 more2024-10-23
CVE-2024-20382 [MEDIUM] CWE-80 CVE-2024-20382: A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) So A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper valida
nvd
CVE-2023-20264P4MEDIUMCVSS 6.1v9.18.1v9.18.1.3+10 more2023-11-01
CVE-2023-20264 [MEDIUM] CWE-601 CVE-2023-20264: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-o A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user who is authenticating to a re
nvd
CVE-2024-20370P4MEDIUMCVSS 6.0v9.17.1v9.17.1.7+38 more2024-10-23
CVE-2024-20370 [MEDIUM] CWE-264 CVE-2024-20370: A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Secu A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to elevate their administrative privileges to root. The attacker would need valid administrative credentials on the device to
nvd
CVE-2021-34787P4MEDIUMCVSS 5.3vn/a2021-10-27
CVE-2021-34787 [MEDIUM] CWE-183 CVE-2021-34787: A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Secu A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices conf
nvd
CVE-2021-34794P4MEDIUMCVSS 5.3vn/a2021-10-27
CVE-2021-34794 [MEDIUM] CWE-284 CVE-2021-34794: A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control function A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could
nvd