Cisco Adaptive Security Appliance Software vulnerabilities

164 known vulnerabilities affecting cisco/cisco_adaptive_security_appliance_software.

Total CVEs
164
CISA KEV
7
actively exploited
Public exploits
3
Exploited in wild
8
Severity breakdown
CRITICAL5HIGH95MEDIUM63LOW1

Vulnerabilities

Page 8 of 9
CVE-2019-1945HIGHCVSS 7.8≥ unspecified, < 9.8.4.72019-08-07
CVE-2019-1945 [HIGH] CWE-20 CVE-2019-1945: Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisor
cvelistv5nvd
CVE-2019-1873HIGHCVSS 8.6≥ unspecified, < 9.4.4.36≥ unspecified, < 9.6.4.29+4 more2019-07-10
CVE-2019-1873 [HIGH] CWE-400 CVE-2019-1873: A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vulnerability is due to incomplete input validation of a Secure Sockets Layer (SSL) or Transport Layer Security (TLS)
cvelistv5nvd
CVE-2019-1706HIGHCVSS 8.6≥ unspecified, < 9.9.2.502019-05-03
CVE-2019-1706 [HIGH] CWE-404 CVE-2019-1706: A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance (ASAv) and Firepower 2100 Series running Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device that results in a denial of service (DoS) condition. The vulnerability i
cvelistv5nvd
CVE-2019-1687HIGHCVSS 7.5≥ unspecified, < 9.4.4.34≥ unspecified, < 9.8.4+1 more2019-05-03
CVE-2019-1687 [HIGH] CWE-20 CVE-2019-1687: A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to an error in TCP-based packet inspect
cvelistv5nvd
CVE-2018-15388HIGHCVSS 8.6≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+2 more2019-05-03
CVE-2018-15388 [HIGH] CWE-400 CVE-2018-15388: A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for existing WebVPN login operations. An attacke
cvelistv5nvd
CVE-2019-1708HIGHCVSS 8.6≥ unspecified, < 9.8.4≥ unspecified, < 9.9.2.50+1 more2019-05-03
CVE-2019-1708 [HIGH] CWE-404 CVE-2019-1708: A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) fe A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (Do
cvelistv5nvd
CVE-2019-1694HIGHCVSS 8.6≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+3 more2019-05-03
CVE-2019-1694 [HIGH] CWE-20 CVE-2019-1694: A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper handling of TCP traffic. An att
cvelistv5nvd
CVE-2019-1697HIGHCVSS 7.5≥ unspecified, < 9.6(4.21)2019-05-03
CVE-2019-1697 [HIGH] CWE-20 CVE-2019-1697: A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are d
cvelistv5nvd
CVE-2019-1713HIGHCVSS 8.8≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+3 more2019-05-03
CVE-2019-1713 [HIGH] CWE-352 CVE-2019-1713: A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Sof A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An a
cvelistv5nvd
CVE-2019-1714HIGHCVSS 8.6≥ unspecified, < 9.8.4≥ unspecified, < 9.9.2.50+1 more2019-05-03
CVE-2019-1714 [HIGH] CWE-255 CVE-2019-1714: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-O A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN
cvelistv5nvd
CVE-2019-1715HIGHCVSS 7.5≥ unspecified, < 9.8.4≥ unspecified, < 9.9.2.502019-05-03
CVE-2019-1715 [HIGH] CWE-332 CVE-2019-1715: A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private k
cvelistv5nvd
CVE-2019-1695MEDIUMCVSS 6.5≥ unspecified, < 9.8.4≥ unspecified, < 9.9.2.50+1 more2019-05-03
CVE-2019-1695 [MEDIUM] CWE-284 CVE-2019-1695: A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected d
cvelistv5nvd
CVE-2019-1693MEDIUMCVSS 6.5≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+3 more2019-05-03
CVE-2019-1693 [MEDIUM] CWE-399 CVE-2019-1693: A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper management of authenticated sessions in the WebVPN portal. An a
cvelistv5nvd
CVE-2019-1705MEDIUMCVSS 5.9≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+3 more2019-05-03
CVE-2019-1705 [MEDIUM] CWE-404 CVE-2019-1705: A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulner
cvelistv5nvd
CVE-2019-1701MEDIUMCVSS 4.8≥ unspecified, < 9.4.4.34≥ unspecified, < 9.6.4.25+3 more2019-05-03
CVE-2019-1701 [MEDIUM] CWE-79 CVE-2019-1701: Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software a Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal of an affected device. The vulnerabilities exist because the software insuff
cvelistv5nvd
CVE-2018-15465HIGHCVSS 8.1vn/a2018-12-24
CVE-2018-15465 [HIGH] CWE-285 CVE-2018-15465: A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software c A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interfa
cvelistv5nvd
CVE-2018-15454HIGHCVSS 8.6Exploitedv9.42018-11-01
CVE-2018-15454 [HIGH] CWE-20 CVE-2018-15454: A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Securit A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is
cvelistv5nvd
CVE-2018-0472HIGHCVSS 8.6vn/a2018-10-05
CVE-2018-0472 [HIGH] CWE-20 CVE-2018-0472: A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco A A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to improper processing of malformed IPsec Authentication Header (AH) or Encapsulating Security Payloa
cvelistv5nvd
CVE-2018-15383HIGHCVSS 7.5vn/a2018-10-05
CVE-2018-15383 [HIGH] CWE-400 CVE-2018-15383: A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Applianc A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the af
cvelistv5nvd
CVE-2018-15397MEDIUMCVSS 6.8vn/a2018-10-05
CVE-2018-15397 [MEDIUM] CWE-320 CVE-2018-15397: A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) conditio
cvelistv5nvd