cbcvebase.

Cisco Firepower Threat Defense Software vulnerabilities

169 known vulnerabilities affecting cisco/cisco_firepower_threat_defense_software.

Total CVEs
169
CISA KEV
4
actively exploited
Public exploits
1
Exploited in wild
5
Severity breakdown
CRITICAL2HIGH82MEDIUM85

Vulnerabilities

Page 1 of 9
CVE-2023-20269P1CRITICALCVSS 9.1KEVRansomwarev6.2.3v6.2.3.1+74 more2023-09-06
CVE-2023-20269 [CRITICAL] CWE-288 CVE-2023-20269: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a
nvd
CVE-2024-20353P1HIGHCVSS 8.6KEVRansomwarev6.2.3v6.2.3.1+78 more2024-04-24
CVE-2024-20353 [HIGH] CWE-835 CVE-2024-20353: A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) So A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking
nvd
CVE-2024-20359P1MEDIUMCVSS 6.0KEVRansomwarev6.2.3v6.2.3.1+78 more2024-04-24
CVE-2024-20359 [MEDIUM] CWE-94 CVE-2024-20359: A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins a A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level priv
nvd
CVE-2024-20481P2MEDIUMCVSS 5.8KEVv6.2.3v6.2.3.1+88 more2024-10-23
CVE-2024-20481 [MEDIUM] CWE-772 CVE-2024-20481: A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnera
nvd
CVE-2025-20363P1CRITICALCVSS 9.0Exploitedv6.2.3v6.2.3.1+92 more2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS,
nvd
CVE-2019-1978P3MEDIUMCVSS 5.8PoC≥ unspecified, < n/a2019-11-05
CVE-2019-1978 [MEDIUM] CWE-264 CVE-2019-1978: A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper reassembly of traffic streams. An attacker could e
nvd
CVE-2021-1518P2HIGHCVSS 8.8vn/a2021-07-22
CVE-2021-1518 [HIGH] CWE-94 CVE-2021-1518: A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is due to insufficient sanitization of user input on specific REST API commands. An attacker could exploit this vulnerab
nvd
CVE-2025-20133P3HIGHCVSS 8.6v6.2.3.14v6.4.0.1+85 more2025-08-14
CVE-2025-20133 [HIGH] CWE-401 CVE-2025-20133: A vulnerability in the management and VPN web servers of the Remote Access SSL VPN feature of Cisco A vulnerability in the management and VPN web servers of the Remote Access SSL VPN feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly stop responding, resulting in a DoS condition. This vulnerability is due to ineffective validation of user-supplied
nvd
CVE-2025-20243P3HIGHCVSS 8.6v6.2.3.14v6.4.0.1+92 more2025-08-14
CVE-2025-20243 [HIGH] CWE-835 CVE-2025-20243: A vulnerability in the management and VPN web servers of Cisco Secure Firewall ASA Software and Secu A vulnerability in the management and VPN web servers of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to improper validation of user-supplied input on an interface with VPN web services. An
nvd
CVE-2024-20342P3HIGHCVSS 8.6v7.0.0v7.0.0.1+30 more2024-10-23
CVE-2024-20342 [HIGH] CWE-1025 CVE-2024-20342: Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort d Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic th
nvd
CVE-2019-1714P3HIGHCVSS 8.6≥ unspecified, < 6.2.3.12≥ unspecified, < 6.3.0.32019-05-03
CVE-2019-1714 [HIGH] CWE-255 CVE-2019-1714: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-O A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN
nvd
CVE-2025-20251P3HIGHCVSS 8.5v6.2.3.14v6.4.0.1+92 more2025-08-14
CVE-2025-20251 [HIGH] CWE-1287 CVE-2025-20251: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security App A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system files are manipulated, new Remote Acc
nvd
CVE-2025-20253P3HIGHCVSS 8.6v6.2.3.14v6.4.0.1+92 more2025-08-14
CVE-2025-20253 [HIGH] CWE-835 CVE-2025-20253: A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Sof A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is due to the improper processing of IKEv2 packets. An attacker could exploit this vulnerabil
nvd
CVE-2025-20263P3HIGHCVSS 8.6v6.2.3.14v6.4.0.1+90 more2025-08-14
CVE-2025-20263 [HIGH] CWE-680 CVE-2025-20263: A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance ( A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. This vulnerability is due to insufficient boundary checks for specific data that is
nvd
CVE-2025-20222P3HIGHCVSS 8.6v6.2.3v6.2.3.9+86 more2025-08-14
CVE-2025-20222 [HIGH] CWE-120 CVE-2025-20222: A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adapt A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of IPv6 packets
nvd
CVE-2025-20136P3HIGHCVSS 8.6v6.2.3.14v6.4.0.1+89 more2025-08-14
CVE-2025-20136 [HIGH] CWE-835 CVE-2025-20136: A vulnerability in the function that performs IPv4 and IPv6 Network Address Translation (NAT) DNS in A vulnerability in the function that performs IPv4 and IPv6 Network Address Translation (NAT) DNS inspection for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of se
nvd
CVE-2025-20239P3HIGHCVSS 8.6v6.2.3v6.2.3.1+92 more2025-08-14
CVE-2025-20239 [HIGH] CWE-401 CVE-2025-20239: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This vul
nvd
CVE-2025-20217P3HIGHCVSS 8.6v7.1.0v7.1.0.1+27 more2025-08-14
CVE-2025-20217 [HIGH] CWE-835 CVE-2025-20217: A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secu A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of traffic that is inspected by an affected
nvd
CVE-2025-20134P3HIGHCVSS 8.6v6.6.5.2v6.4.0.15+6 more2025-08-14
CVE-2025-20134 [HIGH] CWE-415 CVE-2025-20134: A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance ( A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper pa
nvd
CVE-2019-1703P3HIGHCVSS 8.6≥ unspecified, < 6.2.3.122019-05-03
CVE-2019-1703 [HIGH] CWE-400 CVE-2019-1703: A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (F A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error, which may
nvd