cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

237 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
237
CISA KEV
11
actively exploited
Public exploits
9
Exploited in wild
10
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1UNKNOWN12

Vulnerabilities

Page 11 of 12
CVE-2019-1691MEDIUMCVSS 5.8fixed in 6.2.3.42019-02-21
CVE-2019-1691 [MEDIUM] CWE-20 CVE-2019-1691: A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an un A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT detection engine, resulting in a denial of service (DoS) condition. The vulnerability is due to the incomplete error handling of the SSL or TLS packet header during the connectio
nvdcisco
CVE-2019-1669HIGHCVSS 8.6v6.3.0v6.4.02019-01-24
CVE-2019-1669 [HIGH] CWE-693 CVE-2019-1669: A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Soft A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition. The vulnerability exists because the affected software improperly manages system memory resources when inspecti
nvdcisco
CVE-2018-15454HIGHCVSS 8.6Exploited≥ 6.1.0, < 6.1.0.7≥ 6.2.0, < 6.2.0.6+2 more2018-11-01
CVE-2018-15454 [HIGH] CWE-20 CVE-2018-15454: A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Securit A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is
nvd
CVE-2018-0453HIGHCVSS 8.2v5.4.0v6.0.0+5 more2018-10-05
CVE-2018-0453 [HIGH] CWE-264 CVE-2018-0453: A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with root privileges on the Cisco Firepower Management Center (FMC), or through Cisco FMC on other Firepower sensors and
nvd
CVE-2018-15383HIGHCVSS 7.5v6.0v6.0.1+4 more2018-10-05
CVE-2018-15383 [HIGH] CWE-400 CVE-2018-15383: A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Applianc A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the af
nvd
CVE-2018-15390MEDIUMCVSS 6.8≥ 6.2.3.0, ≤ 6.2.3.42018-10-05
CVE-2018-15390 [MEDIUM] CWE-399 CVE-2018-15390: A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to release spinlocks when a device is running low on system
nvdcisco
CVE-2018-15398MEDIUMCVSS 4.0v6.2.02018-10-05
CVE-2018-15398 [MEDIUM] CWE-284 CVE-2018-15398: A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an affected device. The vulnerability is due to errors that could occur wh
nvd
CVE-2018-15399MEDIUMCVSS 6.8v6.2.02018-10-05
CVE-2018-15399 [MEDIUM] CWE-400 CVE-2018-15399: A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cis A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing boundary check i
nvd
CVE-2018-0296HIGHCVSS 7.5KEVPoC≥ 6.0, < 6.1.0≥ 6.2.1, < 6.2.2.3+4 more2018-06-07
CVE-2018-0296 [HIGH] CWE-20 CVE-2018-0296: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an u A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system
nvd
CVE-2018-0297MEDIUMCVSS 5.8v6.0.0v6.1.0+2 more2018-05-17
CVE-2018-0297 [MEDIUM] CWE-693 CVE-2018-0297: A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an un A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to the incorrect handling of TCP SSL packets received out of order. An attacker could exploit this
nvdcisco
CVE-2018-0230HIGHCVSS 8.6v6.2.1v6.2.22018-04-19
CVE-2018-0230 [HIGH] CWE-400 CVE-2018-0230: A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (F A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to the affe
nvd
CVE-2018-0231HIGHCVSS 8.6≥ 6.0, < 6.1.0.6≥ 6.2.1, < 6.2.2.12018-04-19
CVE-2018-0231 [HIGH] CWE-20 CVE-2018-0231: A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance ( A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validatio
nvd
CVE-2018-0228HIGHCVSS 8.6≥ 6.0, < 6.1.0.6≥ 6.2.0, < 6.2.0.5+1 more2018-04-19
CVE-2018-0228 [HIGH] CWE-20 CVE-2018-0228: A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incorrect handling of an internal software lock that
nvd
CVE-2018-0240HIGHCVSS 8.6≥ 6.1.0, ≤ 6.1.0.7≥ 6.2.0, < 6.2.0.5+1 more2018-04-19
CVE-2018-0240 [HIGH] CWE-399 CVE-2018-0240: Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Secu Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to log
nvd
CVE-2018-0227HIGHCVSS 7.5≥ 6.0, ≤ 6.0.1.4≥ 6.1.0, ≤ 6.1.0.52018-04-19
CVE-2018-0227 [HIGH] CWE-295 CVE-2018-0227: A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate A A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification
nvd
CVE-2018-0243MEDIUMCVSS 5.8fixed in 6.2.32018-04-19
CVE-2018-0243 [MEDIUM] CWE-693 CVE-2018-0243: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy that is intended to drop the Server Message Block Version 2 (SMB2) and SMB Version 3 (SMB3) protocols if malware is detected. The vulnerability is due to incorrect detection of an SMB2 or
nvd
CVE-2018-0244MEDIUMCVSS 5.8fixed in 6.2.32018-04-19
CVE-2018-0244 [MEDIUM] CWE-693 CVE-2018-0244: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy to drop the Server Message Block (SMB) protocol if a malware file is detected. The vulnerability is due to how the SMB protocol handles a case in which a large file transfer fails. This ca
nvd
CVE-2018-0254MEDIUMCVSS 5.3v6.1.0.5v6.2.0.2+2 more2018-04-19
CVE-2018-0254 [MEDIUM] CWE-693 CVE-2018-0254: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An atta
nvd
CVE-2018-0138MEDIUMCVSS 5.3v6.1.0v6.2.0+2 more2018-02-08
CVE-2018-0138 [MEDIUM] CWE-693 CVE-2018-0138: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file policies that are configured to block files transmitted to an affected device via the BitTorrent protocol. The vulnerability exists because the affected software does not detect BitTorrent handshake messages correct
nvd
CVE-2018-0101CRITICALCVSS 10.0PoCv6.0.0v6.0.1+4 more2018-01-29
CVE-2018-0101 [CRITICAL] CWE-415 CVE-2018-0101: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security A A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled o
nvd