Cisco Firepower Threat Defense Software vulnerabilities
169 known vulnerabilities affecting cisco/cisco_firepower_threat_defense_software.
Total CVEs
169
CISA KEV
4
actively exploited
Public exploits
1
Exploited in wild
5
Severity breakdown
CRITICAL2HIGH82MEDIUM85
Vulnerabilities
Page 2 of 9
CVE-2023-20244P3HIGHCVSS 8.6v6.2.3v6.2.3.1+68 more2023-11-01
CVE-2023-20244 [HIGH] CWE-771 CVE-2023-20244: A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) Software f
A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain packets when they are sent to the insp
nvd
CVE-2024-20426P3HIGHCVSS 8.6v7.2.0v7.2.0.1+19 more2024-10-23
CVE-2024-20426 [HIGH] CWE-476 CVE-2024-20426: A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient i
nvd
CVE-2024-20402P3HIGHCVSS 8.6v6.2.3v6.2.3.1+85 more2024-10-23
CVE-2024-20402 [HIGH] CWE-788 CVE-2024-20402: A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisc
A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to a logic error in memory manageme
nvd
CVE-2024-20494P3HIGHCVSS 8.6v7.3.0v7.3.1+6 more2024-10-23
CVE-2024-20494 [HIGH] CWE-1287 CVE-2024-20494: A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Sof
A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper data validation
nvd
CVE-2025-20182P3HIGHCVSS 8.6v6.2.3.14v6.4.0.1+84 more2025-05-07
CVE-2025-20182 [HIGH] CWE-787 CVE-2025-20182: A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vu
nvd
CVE-2019-1694P3HIGHCVSS 8.6≥ unspecified, < 6.2.3.12≥ unspecified, < 6.3.0.32019-05-03
CVE-2019-1694 [HIGH] CWE-20 CVE-2019-1694: A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper handling of TCP traffic. An att
nvd
CVE-2023-20086P3HIGHCVSS 8.6v6.2.3v6.2.3.1+69 more2023-11-01
CVE-2023-20086 [HIGH] CWE-248 CVE-2023-20086: A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco F
A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of ICMPv6 messages. An attacker could exploit this vulnerability by sen
nvd
CVE-2023-20095P3HIGHCVSS 8.6v6.2.3v6.2.3.1+57 more2023-11-01
CVE-2023-20095 [HIGH] CWE-772 CVE-2023-20095: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of HTTPS requests. An attacker could ex
nvd
CVE-2024-20495P3HIGHCVSS 8.6v6.2.3.16v6.2.3.17+43 more2024-10-23
CVE-2024-20495 [HIGH] CWE-20 CVE-2024-20495: A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software
A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper v
nvd
CVE-2020-3283P3HIGHCVSS 8.6vn/a2020-05-06
CVE-2020-3283 [HIGH] CWE-119 CVE-2020-3283: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Fi
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communicatio
nvd
CVE-2020-3562P3HIGHCVSS 8.6vn/a2020-10-21
CVE-2020-3562 [HIGH] CWE-119 CVE-2020-3562: A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco
A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation for certain fields of specific SSL/TLS messages. An
nvd
CVE-2019-12675P3HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12675 [HIGH] CWE-216 CVE-2019-12675: Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Softw
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An a
nvd
CVE-2023-20083P3HIGHCVSS 8.6v6.2.3v6.2.3.1+70 more2023-11-01
CVE-2023-20083 [HIGH] CWE-835 CVE-2023-20083: A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Fir
A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of service (DoS) condition. FTD managemen
nvd
CVE-2024-20260P3HIGHCVSS 8.6v6.2.3.7v6.4.0+86 more2024-10-23
CVE-2024-20260 [HIGH] CWE-789 CVE-2024-20260: A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Applian
A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL
nvd
CVE-2021-1223P3HIGHCVSS 7.5vn/a2021-01-13
CVE-2021-1223 [HIGH] CWE-693 CVE-2021-1223: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected de
nvd
CVE-2019-1832P3HIGHCVSS 7.5≥ unspecified, < n/a2019-05-16
CVE-2019-1832 [HIGH] CWE-693 CVE-2019-1832: A vulnerability in the detection engine of Cisco Firepower Threat Defense (FTD) Software could allow
A vulnerability in the detection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies. The vulnerability is due to improper validation of ICMP packets. An attacker could exploit this vulnerability by sending crafted ICMP packets to the affected device. A succ
nvd
CVE-2020-3309P3HIGHCVSS 7.2vn/a2020-05-06
CVE-2020-3309 [HIGH] CWE-20 CVE-2020-3309: A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated
A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by uploading a malicious file to an affected device
nvd
CVE-2022-20730P3HIGHCVSS 7.5vn/a2022-05-03
CVE-2022-20730 [HIGH] CWE-241 CVE-2022-20730: A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) So
A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected devic
nvd
CVE-2019-1708P3HIGHCVSS 8.6≥ unspecified, < 6.2.3.12≥ unspecified, < 6.3.0.32019-05-03
CVE-2019-1708 [HIGH] CWE-404 CVE-2019-1708: A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) fe
A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (Do
nvd
CVE-2021-1402P3HIGHCVSS 8.6vn/a2021-04-29
CVE-2021-1402 [HIGH] CWE-119 CVE-2021-1402: A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs softwa
nvd