cbcvebase.

Cisco Firepower Threat Defense Software vulnerabilities

169 known vulnerabilities affecting cisco/cisco_firepower_threat_defense_software.

Total CVEs
169
CISA KEV
4
actively exploited
Public exploits
1
Exploited in wild
5
Severity breakdown
CRITICAL2HIGH82MEDIUM85

Vulnerabilities

Page 4 of 9
CVE-2018-15462P3HIGHCVSS 7.5≥ unspecified, < 6.2.3.12≥ unspecified, < 6.3.0.32019-05-03
CVE-2018-15462 [HIGH] CWE-399 CVE-2018-15462: A vulnerability in the TCP ingress handler for the data interfaces that are configured with manageme A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an increase in CPU and memory usage, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient ingress T
nvd
CVE-2020-3533P3HIGHCVSS 7.5vn/a2020-10-21
CVE-2020-3533 [HIGH] CWE-400 CVE-2020-3533: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Fir A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly. The vulnerability is due to a lack of sufficient memory management protections under heavy SNMP polling loads. An att
nvd
CVE-2022-20767P3HIGHCVSS 7.5vn/a2022-05-03
CVE-2022-20767 [HIGH] CWE-399 CVE-2022-20767: A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Softwa A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of the DNS reputation enforcement rule. An attacker could exploit this vulnerability by
nvd
CVE-2019-1699P3HIGHCVSS 7.8≥ unspecified, < 6.2.3.12≥ unspecified, < 6.3.0.32019-05-03
CVE-2019-1699 [HIGH] CWE-78 CVE-2019-1699: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into arguments for a specific command. A successful exploit could allo
nvd
CVE-2025-20127P3HIGHCVSS 7.7v7.4.0v7.4.1+4 more2025-08-14
CVE-2025-20127 [HIGH] CWE-404 CVE-2025-20127: A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adapti A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are associated with incoming TLS 1.3 co
nvd
CVE-2021-34755P3HIGHCVSS 7.8vn/a2021-10-27
CVE-2021-34755 [HIGH] CWE-20 CVE-2021-34755: Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-34756P3HIGHCVSS 7.8vn/a2021-10-27
CVE-2021-34756 [HIGH] CWE-20 CVE-2021-34756: Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2025-20244P3HIGHCVSS 7.7v6.2.3.14v6.4.0.1+91 more2025-08-14
CVE-2025-20244 [HIGH] CWE-1287 CVE-2025-20244: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security App A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker that is authenticated as a VPN user to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerab
nvd
CVE-2024-20408P3HIGHCVSS 7.7v6.2.3v6.2.3.1+88 more2024-10-23
CVE-2024-20408 [HIGH] CWE-1287 CVE-2024-20408: A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (A A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need valid remote access VPN user credenti
nvd
CVE-2023-20006P3HIGHCVSS 7.5v7.2.1v7.2.2+1 more2023-06-28
CVE-2023-20006 [HIGH] CWE-681 CVE-2023-20006: A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do
nvd
CVE-2022-20947P3HIGHCVSS 7.5v6.2.3v6.2.3.1+50 more2022-11-15
CVE-2022-20947 [HIGH] CWE-119 CVE-2022-20947: A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper processing of HostSc
nvd
CVE-2024-20339P3HIGHCVSS 7.5v6.2.3v6.2.3.9+78 more2024-10-23
CVE-2024-20339 [HIGH] CWE-476 CVE-2024-20339: A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for C A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an issue that occurs when TLS traffic is processed. An attacker could exploit th
nvd
CVE-2024-20330P3HIGHCVSS 7.5v7.0.0v7.0.0.1+35 more2024-10-23
CVE-2024-20330 [HIGH] CWE-788 CVE-2024-20330: A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat De A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause memory corruption, which could cause the Snort detection engine to restart unexpectedly. This vulnerability is due to improper memo
nvd
CVE-2020-3255P3HIGHCVSS 7.5vn/a2020-05-06
CVE-2020-3255 [HIGH] CWE-400 CVE-2020-3255: A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Softw A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a high rate of IPv4
nvd
CVE-2021-40116P3HIGHCVSS 7.5vn/a2021-10-27
CVE-2021-40116 [HIGH] CWE-241 CVE-2021-40116: Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthent Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints.
nvd
CVE-2022-20751P3HIGHCVSS 7.5vn/a2022-05-03
CVE-2022-20751 [HIGH] CWE-770 CVE-2022-20751: A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) S A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient memory management for certain Snort e
nvd
CVE-2022-20746P3HIGHCVSS 7.5vn/a2022-05-03
CVE-2022-20746 [HIGH] CWE-476 CVE-2022-20746: A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software coul A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper handling of TCP flows. An attacker could exploit this vulnerability by sending a crafted stream of TCP traffic through an a
nvd
CVE-2022-20757P3HIGHCVSS 7.5vn/a2022-05-03
CVE-2022-20757 [HIGH] CWE-770 CVE-2022-20757: A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper traffic handling when platform limits are reached. An attacker could exploit this vulnerability by
nvd
CVE-2022-20729P3HIGHCVSS 7.8vn/a2022-05-03
CVE-2022-20729 [HIGH] CWE-91 CVE-2022-20729: A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject XML into the command parser. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted input in commands. A successful exploit could allow the attacker to inje
nvd
CVE-2019-1704P3HIGHCVSS 7.5≥ unspecified, < 6.2.3.122019-05-03
CVE-2019-1704 [HIGH] CWE-400 CVE-2019-1704: Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine fo Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
nvd