cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

225 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
225
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
16
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1

Vulnerabilities

Page 4 of 12
CVE-2020-3571P3HIGHCVSS 8.6≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.10+1 more2020-10-21
CVE-2020-3571 [HIGH] CWE-400 CVE-2020-3571: A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Softwa A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incomplete input validation upon receiving ICMP packets. An attacker cou
nvd
CVE-2019-1715P3HIGHCVSS 7.5≥ 6.2.1, < 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1715 [HIGH] CWE-332 CVE-2019-1715: A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private k
nvd
CVE-2023-20107P3HIGHCVSS 7.5fixed in 6.4.02023-03-23
CVE-2023-20107 [HIGH] CWE-332 CVE-2023-20107: A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote attacker to cause a cryptographic co
nvd
CVE-2018-0227P3HIGHCVSS 7.5≥ 6.0, ≤ 6.0.1.4≥ 6.1.0, ≤ 6.1.0.52018-04-19
CVE-2018-0227 [HIGH] CWE-295 CVE-2018-0227: A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate A A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification
nvd
CVE-2019-1970P3HIGHCVSS 7.5fixed in 6.4.12019-08-08
CVE-2019-1970 [HIGH] CWE-693 CVE-2019-1970: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors when handling specific SSL/TLS messages. An attacker
nvd
CVE-2022-20685P3HIGHCVSS 7.5v6.2.3v6.2.3.1+42 more2024-11-15
CVE-2022-20685 [HIGH] CWE-190 CVE-2022-20685: A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthentica A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit this vulnerability by sending crafted Modbus traffic thr
nvd
CVE-2020-3167P3HIGHCVSS 7.8≥ 6.2.2, < 6.2.3.13≥ 6.3.0, < 6.4.0.8+1 more2020-02-26
CVE-2020-3167 [HIGH] CWE-78 CVE-2020-3167: A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an auth A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A
nvd
CVE-2024-20268P3HIGHCVSS 7.7v6.6.0v6.6.0.1+45 more2024-10-23
CVE-2024-20268 [HIGH] CWE-231 CVE-2024-20268: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the device. This vulnerability is due to insufficient input validation of SNMP packets. An attacker
nvd
CVE-2021-1448P3HIGHCVSS 7.8≥ 6.4.0, < 6.4.0.10≥ 6.5.0, < 6.5.0.5+1 more2021-04-29
CVE-2021-1448 [HIGH] CWE-20 CVE-2021-1448: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is running in multi-instance mode. This vulnerability is due to insufficient validation of user-supplied command arguments
nvd
CVE-2026-20100P3HIGHCVSS 7.7v6.4.0v6.4.0.1+73 more2026-03-04
CVE-2026-20100 [HIGH] CWE-120 CVE-2026-20100: A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to cause the device to reload unexpectedly, resulting in a denial of service (DoS) co
nvd
CVE-2022-20742P3HIGHCVSS 7.4fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20742 [HIGH] CWE-325 CVE-2022-20742: A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerability is due to an improper implementation of Galois/Counter Mode (GCM) ciphers. An attacker
nvd
CVE-2019-1687P3HIGHCVSS 7.5≥ 6.0.0, < 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1687 [HIGH] CWE-20 CVE-2019-1687: A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to an error in TCP-based packet inspect
nvd
CVE-2020-3554P3HIGHCVSS 7.5≤ 6.2.2≥ 6.3.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3554 [HIGH] CWE-400 CVE-2020-3554: A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory exhaustion condition. An attacker could exploit this vu
nvd
CVE-2021-40114P3HIGHCVSS 7.5fixed in 6.4.0.12≥ 6.5.0, < 6.6.3+1 more2021-10-27
CVE-2021-40114 [HIGH] CWE-770 CVE-2021-40114: Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine proces Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper memory resource management while the Snort detection engine is processing ICMP
nvd
CVE-2023-20063P3HIGHCVSS 8.2≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.17+5 more2023-11-01
CVE-2023-20063 [HIGH] CWE-94 CVE-2023-20063: A vulnerability in the inter-device communication mechanisms between devices that are running Cisco A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affect
nvd
CVE-2021-1504P3HIGHCVSS 7.5≥ 6.5.0, < 6.6.4≥ 6.7.0, < 6.7.0.12021-04-29
CVE-2021-1504 [HIGH] CWE-787 CVE-2021-1504: Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat De Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these
nvd
CVE-2021-1445P3HIGHCVSS 7.5≥ 6.5.0, < 6.6.4≥ 6.7.0, < 6.7.0.12021-04-29
CVE-2021-1445 [HIGH] CWE-787 CVE-2021-1445: Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat De Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these
nvd
CVE-2022-20760P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20760 [HIGH] CWE-400 CVE-2022-20760: A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to a lack of proper processing of incoming requests. An attacker coul
nvd
CVE-2019-1709P3HIGHCVSS 7.8v6.0.0v6.0.1+5 more2019-05-03
CVE-2019-1709 [HIGH] CWE-78 CVE-2019-1709: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into arguments for a specific command. A successful exploit could allo
nvd
CVE-2021-1573P3HIGHCVSS 7.5≤ 6.2.2≥ 6.2.3, < 6.4.0.13+3 more2022-01-11
CVE-2021-1573 [HIGH] CWE-121 CVE-2021-1573: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit t
nvd
Cisco Firepower Threat Defense vulnerabilities | cvebase