Cisco Firepower Threat Defense Software vulnerabilities
169 known vulnerabilities affecting cisco/cisco_firepower_threat_defense_software.
Total CVEs
169
CISA KEV
4
actively exploited
Public exploits
1
Exploited in wild
5
Severity breakdown
CRITICAL2HIGH82MEDIUM85
Vulnerabilities
Page 3 of 9
CVE-2019-1669P3HIGHCVSS 8.6vn/a2019-01-24
CVE-2019-1669 [HIGH] CWE-693 CVE-2019-1669: A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Soft
A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition. The vulnerability exists because the affected software improperly manages system memory resources when inspecti
nvd
CVE-2023-20042P3HIGHCVSS 8.6v7.0.0v7.0.0.1+19 more2023-11-01
CVE-2023-20042 [HIGH] CWE-404 CVE-2023-20042: A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Softwar
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handl
nvd
CVE-2024-20412P3HIGHCVSS 8.4v7.1.0v7.1.0.1+21 more2024-10-23
CVE-2024-20412 [HIGH] CWE-259 CVE-2024-20412: A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 310
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials.
This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could expl
nvd
CVE-2019-12627P3HIGHCVSS 7.5≥ unspecified, < 6.4.0.42019-08-21
CVE-2019-12627 [HIGH] CWE-284 CVE-2019-12627: A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD)
A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending crafted traffic to a
nvd
CVE-2021-34754P3HIGHCVSS 7.5vn/a2021-10-27
CVE-2021-34754 [HIGH] CWE-284 CVE-2021-34754: Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic f
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attac
nvd
CVE-2020-3189P3HIGHCVSS 8.6vn/a2020-05-06
CVE-2020-3189 [HIGH] CWE-400 CVE-2020-3189: A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Sof
A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behaviors or device crashes. The vulnerability is due to the system memory not being properly freed fo
nvd
CVE-2020-3563P3HIGHCVSS 8.6vn/a2020-10-21
CVE-2020-3563 [HIGH] CWE-400 CVE-2020-3563: A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Softw
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a large number of TC
nvd
CVE-2020-3571P3HIGHCVSS 8.6vn/a2020-10-21
CVE-2020-3571 [HIGH] CWE-400 CVE-2020-3571: A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Softwa
A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incomplete input validation upon receiving ICMP packets. An attacker cou
nvd
CVE-2019-1715P3HIGHCVSS 7.5≥ unspecified, < 6.2.3.12≥ unspecified, < 6.3.0.32019-05-03
CVE-2019-1715 [HIGH] CWE-332 CVE-2019-1715: A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private k
nvd
CVE-2019-1970P3HIGHCVSS 7.5≥ unspecified, < n/a2019-08-08
CVE-2019-1970 [HIGH] CWE-693 CVE-2019-1970: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors when handling specific SSL/TLS messages. An attacker
nvd
CVE-2022-20685P3HIGHCVSS 7.5v6.2.3.14v6.4.0.1+42 more2024-11-15
CVE-2022-20685 [HIGH] CWE-190 CVE-2022-20685: A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthentica
A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit this vulnerability by sending crafted Modbus traffic thr
nvd
CVE-2024-20268P3HIGHCVSS 7.7v6.6.0v6.6.0.1+45 more2024-10-23
CVE-2024-20268 [HIGH] CWE-231 CVE-2024-20268: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the device.
This vulnerability is due to insufficient input validation of SNMP packets. An attacker
nvd
CVE-2020-3312P3HIGHCVSS 7.5vn/a2020-05-06
CVE-2020-3312 [HIGH] CWE-284 CVE-2020-3312: A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Soft
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending cra
nvd
CVE-2021-1448P3HIGHCVSS 7.8vn/a2021-04-29
CVE-2021-1448 [HIGH] CWE-20 CVE-2021-1448: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is running in multi-instance mode. This vulnerability is due to insufficient validation of user-supplied command arguments
nvd
CVE-2021-40114P3HIGHCVSS 7.5vn/a2021-10-27
CVE-2021-40114 [HIGH] CWE-770 CVE-2021-40114: Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine proces
Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper memory resource management while the Snort detection engine is processing ICMP
nvd
CVE-2023-20063P3HIGHCVSS 8.2v6.2.3.14v6.4.0.1+88 more2023-11-01
CVE-2023-20063 [HIGH] CWE-94 CVE-2023-20063: A vulnerability in the inter-device communication mechanisms between devices that are running Cisco
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affect
nvd
CVE-2019-1709P3HIGHCVSS 7.8≥ unspecified, < 6.2.3.122019-05-03
CVE-2019-1709 [HIGH] CWE-78 CVE-2019-1709: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into arguments for a specific command. A successful exploit could allo
nvd
CVE-2021-1573P3HIGHCVSS 7.5≥ unspecified, < 6.6.52022-01-11
CVE-2021-1573 [HIGH] CWE-121 CVE-2021-1573: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit t
nvd
CVE-2021-34704P3HIGHCVSS 7.5≥ unspecified, < 6.6.52022-01-11
CVE-2021-34704 [HIGH] CWE-121 CVE-2021-34704: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2024-20351P3HIGHCVSS 7.5v6.2.3.14v6.4.0.1+83 more2024-10-23
CVE-2024-20351 [HIGH] CWE-400 CVE-2024-20351: A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firep
A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be dropped, resulting in a denial of service (DoS) condition.
This vulnerability is due to the improp
nvd