cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

225 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
225
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
16
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1

Vulnerabilities

Page 3 of 12
CVE-2020-3196P3HIGHCVSS 8.6≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-05-06
CVE-2020-3196 [HIGH] CWE-400 CVE-2020-3196: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Ad A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of service (DoS) condition. The vulnerabilit
nvd
CVE-2020-3283P3HIGHCVSS 8.6≥ 6.4.0, < 6.4.0.92020-05-06
CVE-2020-3283 [HIGH] CWE-119 CVE-2020-3283: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Fi A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communicatio
nvd
CVE-2020-3373P3HIGHCVSS 8.6v6.6.0.12020-10-21
CVE-2020-3373 [HIGH] CWE-400 CVE-2020-3373: A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. This memory leak could prevent traffic from being processed through the device, resulting in a denia
nvd
CVE-2020-3562P3HIGHCVSS 8.6v6.3.0v6.4.0+1 more2020-10-21
CVE-2020-3562 [HIGH] CWE-119 CVE-2020-3562: A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation for certain fields of specific SSL/TLS messages. An
nvd
CVE-2019-12675P3HIGHCVSS 8.8fixed in 6.4.0.22019-10-02
CVE-2019-12675 [HIGH] CWE-216 CVE-2019-12675: Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Softw Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An a
nvd
CVE-2023-20083P3HIGHCVSS 8.6≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.17+6 more2023-11-01
CVE-2023-20083 [HIGH] CWE-835 CVE-2023-20083: A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Fir A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of service (DoS) condition. FTD managemen
nvd
CVE-2021-34793P3HIGHCVSS 8.6fixed in 6.4.0.13≥ 6.5.0, < 6.6.5+1 more2021-10-27
CVE-2021-34793 [HIGH] CWE-924 CVE-2021-34793: A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepo A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is due to incorrect handling of certai
nvd
CVE-2020-3549P3HIGHCVSS 8.1fixed in 6.6.12020-10-21
CVE-2020-3549 [HIGH] CWE-326 CVE-2020-3549: A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software an A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due to insufficient sftunnel negotiation protection during initial device registration. An attacke
nvd
CVE-2021-1223P3HIGHCVSS 7.5fixed in 6.7.02021-01-13
CVE-2021-1223 [HIGH] CWE-693 CVE-2021-1223: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected de
nvd
CVE-2022-20730P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20730 [HIGH] CWE-241 CVE-2022-20730: A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) So A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected devic
nvd
CVE-2019-1708P3HIGHCVSS 8.6≥ 6.2.2, ≤ 6.2.3.12≥ 6.3.0, ≤ 6.3.0.32019-05-03
CVE-2019-1708 [HIGH] CWE-404 CVE-2019-1708: A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) fe A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (Do
nvd
CVE-2020-3572P3HIGHCVSS 8.6fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+1 more2020-10-21
CVE-2020-3572 [HIGH] CWE-400 CVE-2020-3572: A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software a A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak when closing SSL/TLS connections in a specific s
nvd
CVE-2021-1402P3HIGHCVSS 8.6≥ 6.3.0, < 6.4.0≥ 6.5.0, < 6.6.02021-04-29
CVE-2021-1402 [HIGH] CWE-119 CVE-2021-1402: A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs softwa
nvd
CVE-2019-1669P3HIGHCVSS 8.6v6.3.0v6.4.02019-01-24
CVE-2019-1669 [HIGH] CWE-693 CVE-2019-1669: A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Soft A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition. The vulnerability exists because the affected software improperly manages system memory resources when inspecti
nvd
CVE-2023-20042P3HIGHCVSS 8.6v7.0.0v7.0.0.1+19 more2023-11-01
CVE-2023-20042 [HIGH] CWE-404 CVE-2023-20042: A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Softwar A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handl
nvd
CVE-2024-20412P3HIGHCVSS 8.4v7.1.0v7.1.0.1+21 more2024-10-23
CVE-2024-20412 [HIGH] CWE-259 CVE-2024-20412: A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 310 A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could expl
nvd
CVE-2019-12627P3HIGHCVSS 7.5fixed in 6.4.0.42019-08-21
CVE-2019-12627 [HIGH] CWE-284 CVE-2019-12627: A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending crafted traffic to a
nvd
CVE-2021-34754P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5.1+2 more2021-10-27
CVE-2021-34754 [HIGH] CWE-284 CVE-2021-34754: Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic f Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attac
nvd
CVE-2020-3189P3HIGHCVSS 8.6v6.2.3.12v6.2.3.13+2 more2020-05-06
CVE-2020-3189 [HIGH] CWE-400 CVE-2020-3189: A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Sof A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behaviors or device crashes. The vulnerability is due to the system memory not being properly freed fo
nvd
CVE-2020-3563P3HIGHCVSS 8.6≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.10+1 more2020-10-21
CVE-2020-3563 [HIGH] CWE-400 CVE-2020-3563: A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Softw A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a large number of TC
nvd
Cisco Firepower Threat Defense vulnerabilities | cvebase