cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

225 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
225
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
16
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1

Vulnerabilities

Page 5 of 12
CVE-2021-34704P3HIGHCVSS 7.5≥ 6.7.0, < 6.7.0.3v7.0.02022-01-11
CVE-2021-34704 [HIGH] CWE-121 CVE-2021-34704: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2021-40118P3HIGHCVSS 7.5fixed in 6.4.0.13≥ 6.5.0, < 6.6.5+2 more2021-10-27
CVE-2021-40118 [HIGH] CWE-121 CVE-2021-40118: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit
nvd
CVE-2019-12699P3HIGHCVSS 7.8≤ 6.1.0≥ 6.2.0, < 6.2.3.14+1 more2019-10-02
CVE-2019-12699 [HIGH] CWE-20 CVE-2019-12699: Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by incl
nvd
CVE-2018-15462P3HIGHCVSS 7.5fixed in 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2018-15462 [HIGH] CWE-399 CVE-2018-15462: A vulnerability in the TCP ingress handler for the data interfaces that are configured with manageme A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an increase in CPU and memory usage, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient ingress T
nvd
CVE-2019-1697P3HIGHCVSS 7.5fixed in 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1697 [HIGH] CWE-20 CVE-2019-1697: A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are d
nvd
CVE-2020-3254P3HIGHCVSS 7.5≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+1 more2020-05-06
CVE-2020-3254 [HIGH] CWE-400 CVE-2020-3254: Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Ad Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory mana
nvd
CVE-2020-3298P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-05-06
CVE-2020-3298 [HIGH] CWE-125 CVE-2020-3298: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memor
nvd
CVE-2019-12673P3HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.42019-10-02
CVE-2019-12673 [HIGH] CWE-119 CVE-2019-12673: A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Fir A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of FTP data. An attacker could exploit this vuln
nvd
CVE-2020-3533P3HIGHCVSS 7.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3533 [HIGH] CWE-400 CVE-2020-3533: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Fir A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly. The vulnerability is due to a lack of sufficient memory management protections under heavy SNMP polling loads. An att
nvd
CVE-2022-20767P3HIGHCVSS 7.5fixed in 7.0.2v7.1.02022-05-03
CVE-2022-20767 [HIGH] CWE-399 CVE-2022-20767: A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Softwa A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of the DNS reputation enforcement rule. An attacker could exploit this vulnerability by
nvd
CVE-2021-34783P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34783 [HIGH] CWE-119 CVE-2021-34783: A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance ( A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient validation of SS
nvd
CVE-2022-20745P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20745 [HIGH] CWE-20 CVE-2022-20745: A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Secur A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS request
nvd
CVE-2025-20127P3HIGHCVSS 7.7v7.4.0v7.4.1+4 more2025-08-14
CVE-2025-20127 [HIGH] CWE-404 CVE-2025-20127: A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adapti A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are associated with incoming TLS 1.3 co
nvd
CVE-2021-34755P3HIGHCVSS 7.8≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34755 [HIGH] CWE-20 CVE-2021-34755: Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-34756P3HIGHCVSS 7.8≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34756 [HIGH] CWE-20 CVE-2021-34756: Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2024-20408P3HIGHCVSS 7.7v6.2.3v6.2.3.1+88 more2024-10-23
CVE-2024-20408 [HIGH] CWE-1287 CVE-2024-20408: A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (A A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need valid remote access VPN user credenti
nvd
CVE-2023-20006P3HIGHCVSS 7.5v7.2.1v7.2.2+1 more2023-06-28
CVE-2023-20006 [HIGH] CWE-681 CVE-2023-20006: A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do
nvd
CVE-2022-20947P3HIGHCVSS 7.5v6.1.0v6.1.0.1+84 more2022-11-15
CVE-2022-20947 [HIGH] CWE-119 CVE-2022-20947: A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper processing of HostSc
nvd
CVE-2024-20330P3HIGHCVSS 7.5v7.0.0.0v7.0.0.1+35 more2024-10-23
CVE-2024-20330 [HIGH] CWE-788 CVE-2024-20330: A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat De A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause memory corruption, which could cause the Snort detection engine to restart unexpectedly. This vulnerability is due to improper memo
nvd
CVE-2018-15383P3HIGHCVSS 7.5v6.0v6.0.1+4 more2018-10-05
CVE-2018-15383 [HIGH] CWE-400 CVE-2018-15383: A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Applianc A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the af
nvd
Cisco Firepower Threat Defense vulnerabilities | cvebase