Cisco Firepower Threat Defense Software vulnerabilities
169 known vulnerabilities affecting cisco/cisco_firepower_threat_defense_software.
Total CVEs
169
CISA KEV
4
actively exploited
Public exploits
1
Exploited in wild
5
Severity breakdown
CRITICAL2HIGH82MEDIUM85
Vulnerabilities
Page 9 of 9
CVE-2020-3308P4MEDIUMCVSS 4.9vn/a2020-05-06
CVE-2020-3308 [MEDIUM] CWE-347 CVE-2020-3308: A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD)
A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker
nvd
CVE-2022-20748P4MEDIUMCVSS 5.3vn/a2022-05-03
CVE-2022-20748 [MEDIUM] CWE-664 CVE-2022-20748: A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Softwa
A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficient error handling in the local malware analysis process of an affected device. An attacker c
nvd
CVE-2020-3310P4MEDIUMCVSS 4.9vn/a2020-05-06
CVE-2020-3310 [MEDIUM] CWE-119 CVE-2020-3310: A vulnerability in the XML parser code of Cisco Firepower Device Manager On-Box software could allow
A vulnerability in the XML parser code of Cisco Firepower Device Manager On-Box software could allow an authenticated, remote attacker to cause an affected system to become unstable or reload. The vulnerability is due to insufficient hardening of the XML parser configuration. An attacker could exploit this vulnerability in multiple ways using a malici
nvd
CVE-2023-20247P4MEDIUMCVSS 4.3v6.2.3v6.2.3.1+70 more2023-11-01
CVE-2023-20247 [MEDIUM] CWE-288 CVE-2023-20247: A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Soft
A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and password. This vulnerability is due to i
nvd
CVE-2023-20275P4MEDIUMCVSS 4.3v6.2.3v6.2.3.1+71 more2023-12-12
CVE-2023-20275 [MEDIUM] CWE-346 CVE-2023-20275: A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Softwar
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the packet's inner source IP address after
nvd
CVE-2019-1701P4MEDIUMCVSS 4.8≥ unspecified, < 6.2.3.12≥ unspecified, < 6.3.0.32019-05-03
CVE-2019-1701 [MEDIUM] CWE-79 CVE-2019-1701: Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software a
Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal of an affected device. The vulnerabilities exist because the software insuff
nvd
CVE-2025-20135P4MEDIUMCVSS 4.3v6.2.3.14v6.4.0.1+89 more2025-08-14
CVE-2025-20135 [MEDIUM] CWE-401 CVE-2025-20135: A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Applianc
A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to exhaust available memory.
This vulnerability is due to improper validation of incoming DHCP packets. An attacker could explo
nvd
CVE-2023-20070P4MEDIUMCVSS 4.0v7.2.0v7.2.0.12023-11-01
CVE-2023-20070 [MEDIUM] CWE-244 CVE-2023-20070: A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software c
A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability is due to a logic error in how memory allocations are handled during a TLS 1.3 session. Under specific, time-based constra
nvd
CVE-2023-20177P4MEDIUMCVSS 4.0v7.0.0v7.0.0.1+19 more2023-11-01
CVE-2023-20177 [MEDIUM] CWE-244 CVE-2023-20177: A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Softwa
A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability exists beca
nvd
← Previous9 / 9