cbcvebase.

Cisco Secure Firewall Adaptive Security Appliance Software vulnerabilities

29 known vulnerabilities affecting cisco/cisco_secure_firewall_adaptive_security_appliance_software.

Total CVEs
29
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH10MEDIUM18

Vulnerabilities

Page 1 of 2
CVE-2025-20333P1CRITICALCVSS 9.9KEVv9.8.1v9.8.1.5+233 more2025-09-25
CVE-2025-20333 [CRITICAL] CWE-120 CVE-2025-20333: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Sof A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests.
nvd
CVE-2026-20082P3HIGHCVSS 8.6v9.20.4.142026-03-04
CVE-2026-20082 [HIGH] CWE-772 CVE-2026-20082: A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause incoming TCP SYN packets to be dropped incorrectly. This vulnerability is due to improper handling of new, incoming TCP connections that are destined to manageme
nvd
CVE-2026-20103P3HIGHCVSS 8.6v9.12.4.48v9.12.4.50+95 more2026-03-04
CVE-2026-20103 [HIGH] CWE-770 CVE-2026-20103: A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access SSL VPN connections. This does no
nvd
CVE-2026-20039P3HIGHCVSS 8.6v9.12.3v9.12.1+140 more2026-03-04
CVE-2026-20039 [HIGH] CWE-244 CVE-2026-20039: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Sof A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to ineffective memory management of the VPN web
nvd
CVE-2026-20012P3HIGHCVSS 8.6v9.8.1v9.8.1.5+233 more2026-03-25
CVE-2026-20012 [HIGH] CWE-401 CVE-2026-20012: A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) co
nvd
CVE-2026-20101P3HIGHCVSS 8.6v9.12.1v9.12.1.2+145 more2026-03-04
CVE-2026-20101 [HIGH] CWE-330 CVE-2026-20101: A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software a A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could ex
nvd
CVE-2026-20014P3HIGHCVSS 7.7v9.18.1v9.18.1.3+66 more2026-03-04
CVE-2026-20014 [HIGH] CWE-401 CVE-2026-20014: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to the imp
nvd
CVE-2026-20105P3HIGHCVSS 7.7v9.12.1v9.12.1.2+145 more2026-03-04
CVE-2026-20105 [HIGH] CWE-401 CVE-2026-20105: A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaust device memory resulting in a denial of service (DoS) condition.This does not affect the man
nvd
CVE-2026-20100P3HIGHCVSS 7.7v9.12.1v9.12.1.2+145 more2026-03-04
CVE-2026-20100 [HIGH] CWE-120 CVE-2026-20100: A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to cause the device to reload unexpectedly, resulting in a denial of service (DoS) co
nvd
CVE-2026-20049P3HIGHCVSS 7.7v9.12.4.7v9.12.4.10+129 more2026-03-04
CVE-2026-20049 [HIGH] CWE-131 CVE-2026-20049: A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange versi A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affec
nvd
CVE-2026-20099P3MEDIUMCVSS 6.7v9.12.2v9.12.1+133 more2026-02-25
CVE-2026-20099 [MEDIUM] CWE-78 CVE-2026-20099: A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Mana A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. This vulnerability is due to insufficient input validation of command argume
nvd
CVE-2026-20062P3HIGHCVSS 7.2v9.17.1v9.17.1.7+71 more2026-03-04
CVE-2026-20062 [HIGH] CWE-279 CVE-2026-20062: A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in mu A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker with administrative privileges in one context to copy files to or from another context, including configuration files. This vulnerability is due to improper access controls for Secure Copy
nvd
CVE-2024-20358P3MEDIUMCVSS 6.7v9.8.1v9.8.1.5+233 more2024-04-24
CVE-2024-20358 [MEDIUM] CWE-78 CVE-2024-20358: A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is availab A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. Administrator-level privileges are requ
nvd
CVE-2026-20073P3MEDIUMCVSS 5.8v9.12.3v9.12.1+157 more2026-03-04
CVE-2026-20073 [MEDIUM] CWE-284 CVE-2026-20073: A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be denied through an affected device. This vulnerability is due to improper error handling when an affected device that is joining a c
nvd
CVE-2026-20013P3MEDIUMCVSS 5.8v9.12.1v9.12.1.2+147 more2026-03-04
CVE-2026-20013 [MEDIUM] CWE-401 CVE-2026-20013: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to memory exhaustion caused by not fre
nvd
CVE-2026-20015P3MEDIUMCVSS 5.8v9.18.1v9.18.1.3+55 more2026-03-04
CVE-2026-20015 [MEDIUM] CWE-401 CVE-2026-20015: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network. This vulnerability is due to a memory leak when parsing IKEv2 packets
nvd
CVE-2026-20008P3MEDIUMCVSS 6.0v9.12.3v9.12.1+145 more2026-03-04
CVE-2026-20008 [MEDIUM] CWE-78 CVE-2026-20008: A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Se A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root. This vulnerability exists because use
nvd
CVE-2026-20009P4MEDIUMCVSS 5.3v9.17.1v9.17.1.7+80 more2026-03-04
CVE-2026-20009 [MEDIUM] CWE-138 CVE-2026-20009: A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA device and execute commands as a specific user. This vulnerability is due to insufficient va
nvd
CVE-2026-20070P4MEDIUMCVSS 6.1v9.12.3v9.12.1+159 more2026-03-04
CVE-2026-20070 [MEDIUM] CWE-80 CVE-2026-20070: A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due
nvd
CVE-2026-20022P4MEDIUMCVSS 6.5v9.12.1v9.12.1.2+161 more2026-03-04
CVE-2026-20022 [MEDIUM] CWE-823 CVE-2026-20022: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf canon. This vulnerability is due to
nvd
Cisco Secure Firewall Adaptive Security Appliance Software vulnerabilities | cvebase