Cisco Secure Firewall Threat Defense Software vulnerabilities
46 known vulnerabilities affecting cisco/cisco_secure_firewall_threat_defense_software.
Total CVEs
46
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH8MEDIUM37
Vulnerabilities
Page 2 of 3
CVE-2026-20013P3MEDIUMCVSS 5.8v6.4.0v6.4.0.1+73 more2026-03-04
CVE-2026-20013 [MEDIUM] CWE-401 CVE-2026-20013: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network.
This vulnerability is due to memory exhaustion caused by not fre
nvd
CVE-2026-20015P3MEDIUMCVSS 5.8v7.2.0v7.2.0.1+32 more2026-03-04
CVE-2026-20015 [MEDIUM] CWE-401 CVE-2026-20015: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network.
This vulnerability is due to a memory leak when parsing IKEv2 packets
nvd
CVE-2026-20007P3MEDIUMCVSS 5.8v6.4.0.1v6.4.0.2+71 more2026-03-04
CVE-2026-20007 [MEDIUM] CWE-284 CVE-2026-20007: A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat De
A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network that should have been dropped.
This vulnerability is due to a logic error in the integration of the Snort Engine
nvd
CVE-2026-20008P3MEDIUMCVSS 6.0v6.4.0.1v6.4.0.2+73 more2026-03-04
CVE-2026-20008 [MEDIUM] CWE-78 CVE-2026-20008: A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Se
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root.
This vulnerability exists because use
nvd
CVE-2026-20005P3MEDIUMCVSS 5.8v7.6.0v7.6.1+5 more2026-03-04
CVE-2026-20005 [MEDIUM] CWE-392 CVE-2026-20005: Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could a
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to incomplete parsing of the SSL handshake ingress packets. An attacker could explo
nvd
CVE-2026-20054P3MEDIUMCVSS 5.8v7.2.0v7.2.0.1+35 more2026-03-04
CVE-2026-20054 [MEDIUM] CWE-835 CVE-2026-20054: Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to improper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort
nvd
CVE-2026-20068P3MEDIUMCVSS 5.8v7.2.4v7.2.5+26 more2026-03-04
CVE-2026-20068 [MEDIUM] CWE-248 CVE-2026-20068: Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could a
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to incomplete error checking when parsing remote procedure call (RPC) data. An att
nvd
CVE-2026-20058P3MEDIUMCVSS 5.8v7.2.0v7.2.0.1+35 more2026-03-04
CVE-2026-20058 [MEDIUM] CWE-786 CVE-2026-20058: Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow
Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
These vulnerabilities are due to improper error checking when decompressing VBA data. An attacker could exploit these vulnerabilities by sending crafted VBA data to th
nvd
CVE-2026-20065P3MEDIUMCVSS 5.8v7.0.0v7.0.0.1+48 more2026-03-04
CVE-2026-20065 [MEDIUM] CWE-667 CVE-2026-20065: Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could a
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to an error in the binder module initialization logic of the Snort Detection Engin
nvd
CVE-2025-20360P3MEDIUMCVSS 5.8v7.3.0v7.3.1+13 more2025-10-15
CVE-2025-20360 [MEDIUM] CWE-805 CVE-2025-20360: Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart.
This vulnerability is due to a lack of complete error checking when the MIME fields of the HTTP header are parsed. An attacker could exploit this vulnerability by
nvd
CVE-2026-20026P4MEDIUMCVSS 5.8v7.0.0v7.0.0.1+55 more2026-01-07
CVE-2026-20026 [MEDIUM] CWE-415 CVE-2026-20026: Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests t
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection.
This vulnerability is due to an error in buffer handling logic when p
nvd
CVE-2026-20057P4MEDIUMCVSS 5.8v7.2.0v7.2.0.1+35 more2026-03-04
CVE-2026-20057 [MEDIUM] CWE-369 CVE-2026-20057: Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications
Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to lack of proper error checking when decompressing VBA data. An attacker could exploit this vulnerability
nvd
CVE-2026-20006P4MEDIUMCVSS 5.8v7.2.0v7.2.0.1+31 more2026-03-04
CVE-2026-20006 [MEDIUM] CWE-388 CVE-2026-20006: A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secur
A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper implementa
nvd
CVE-2026-20070P4MEDIUMCVSS 6.1v6.4.0.1v6.4.0.2+73 more2026-03-04
CVE-2026-20070 [MEDIUM] CWE-80 CVE-2026-20070: A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device.
This vulnerability is due
nvd
CVE-2026-20022P4MEDIUMCVSS 6.5v6.4.0v6.4.0.1+74 more2026-03-04
CVE-2026-20022 [MEDIUM] CWE-823 CVE-2026-20022: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf canon.
This vulnerability is due to
nvd
CVE-2026-20052P4MEDIUMCVSS 5.8v7.4.0v7.4.1+4 more2026-03-04
CVE-2026-20052 [MEDIUM] CWE-788 CVE-2026-20052: A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure F
A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart.
This vulnerability is due to a logic error in memory management when a device is performing Snort 3 SSL packet ins
nvd
CVE-2026-20102P4MEDIUMCVSS 6.1v7.0.0v7.0.0.1+6 more2026-03-04
CVE-2026-20102 [MEDIUM] CWE-79 CVE-2026-20102: A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software a
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based information.
This vulnerability is due t
nvd
CVE-2026-20027P4MEDIUMCVSS 5.3v7.0.0v7.0.0.1+55 more2026-01-07
CVE-2026-20027 [MEDIUM] CWE-200 CVE-2026-20027: Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that c
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection.
This vulnerability is due to an error in buffer handling logic when p
nvd
CVE-2026-20106P4MEDIUMCVSS 5.3v6.4.0v6.4.0.1+73 more2026-03-04
CVE-2026-20106 [MEDIUM] CWE-401 CVE-2026-20106: A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure
A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition requiring a manual reboot.
nvd
CVE-2026-20023P4MEDIUMCVSS 6.5v6.4.0v6.4.0.1+73 more2026-03-04
CVE-2026-20023 [MEDIUM] CWE-787 CVE-2026-20023: A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to corrupt memory on an affected device, resulting in a denial of service (DoS) condition.
This vulnerability is due to memory corruption wh
nvd