cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

225 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
225
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
16
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1

Vulnerabilities

Page 6 of 12
CVE-2019-12698P3HIGHCVSS 7.5fixed in 6.2.3.15≥ 6.3.0, < 6.3.0.5+1 more2019-10-02
CVE-2019-12698 [HIGH] CWE-400 CVE-2019-12698: A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for a specific WebVPN HTTP page request. An attacker c
nvd
CVE-2020-3195P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.9≥ 6.5.0, < 6.5.0.52020-05-06
CVE-2020-3195 [HIGH] CWE-400 CVE-2020-3195: A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security App A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to incorrect processing of certain OSPF packets. An attacker cou
nvd
CVE-2019-12678P3HIGHCVSS 7.5fixed in 6.2.3.15≥ 6.3.0, < 6.3.0.4+1 more2019-10-02
CVE-2019-12678 [HIGH] CWE-191 CVE-2019-12678: A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Securit A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper parsing of SIP messages
nvd
CVE-2020-3255P3HIGHCVSS 7.5≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+1 more2020-05-06
CVE-2020-3255 [HIGH] CWE-400 CVE-2020-3255: A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Softw A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a high rate of IPv4
nvd
CVE-2020-3555P3HIGHCVSS 7.5≤ 6.2.2≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3555 [HIGH] CWE-404 CVE-2020-3555: A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a watchdog timeout and crash d
nvd
CVE-2021-40117P3HIGHCVSS 7.5fixed in 6.2.3.17≥ 6.3.0, < 6.4.0.13+3 more2021-10-27
CVE-2021-40117 [HIGH] CWE-119 CVE-2021-40117: A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incoming SSL/TLS packets are not properly processed. An at
nvd
CVE-2020-3528P3HIGHCVSS 7.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3528 [HIGH] CWE-400 CVE-2020-3528: A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance ( A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validatio
nvd
CVE-2021-40116P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5.1+2 more2021-10-27
CVE-2021-40116 [HIGH] CWE-241 CVE-2021-40116: Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthent Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints.
nvd
CVE-2022-20751P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20751 [HIGH] CWE-770 CVE-2022-20751: A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) S A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient memory management for certain Snort e
nvd
CVE-2022-20746P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20746 [HIGH] CWE-476 CVE-2022-20746: A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software coul A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper handling of TCP flows. An attacker could exploit this vulnerability by sending a crafted stream of TCP traffic through an a
nvd
CVE-2022-20757P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20757 [HIGH] CWE-770 CVE-2022-20757: A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper traffic handling when platform limits are reached. An attacker could exploit this vulnerability by
nvd
CVE-2022-20729P3HIGHCVSS 7.8fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20729 [HIGH] CWE-91 CVE-2022-20729: A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject XML into the command parser. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted input in commands. A successful exploit could allow the attacker to inje
nvd
CVE-2022-20795P3HIGHCVSS 7.5≤ 7.0.1≥ 7.1.0.0, ≤ 7.1.0.12022-04-21
CVE-2022-20795 [HIGH] CWE-345 CVE-2022-20795: A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processi
nvd
CVE-2017-6632P3HIGHCVSS 7.5v5.3.0v5.4.0+9 more2017-05-22
CVE-2017-6632 [HIGH] CWE-399 CVE-2017-6632: A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePO A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging of certain TCP packets by the affecte
nvd
CVE-2019-1704P3HIGHCVSS 7.5≥ 6.0.0, < 6.2.3.122019-05-03
CVE-2019-1704 [HIGH] CWE-400 CVE-2019-1704: Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine fo Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3179P3HIGHCVSS 7.5≥ 6.3.0, < 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3179 [HIGH] CWE-415 CVE-2020-3179: A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Fir A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory handling error when GRE over IPv6 traffic is processed. An attack
nvd
CVE-2021-1422P3HIGHCVSS 7.7v7.0.0.02021-07-16
CVE-2021-1422 [HIGH] CWE-617 CVE-2021-1422: A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Softw A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle position to cause an unexpected reload of the device that results in a denial of service (DoS) condit
nvd
CVE-2021-34792P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34792 [HIGH] CWE-400 CVE-2021-34792: A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Fir A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacke
nvd
CVE-2021-34781P3HIGHCVSS 7.5≥ 6.3.0, < 6.4.0.13≥ 6.5.0, < 6.6.5+2 more2021-10-27
CVE-2021-34781 [HIGH] CWE-119 CVE-2021-34781: A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepow A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an SSH session fails to be establishe
nvd
CVE-2021-1501P3HIGHCVSS 7.5≥ 6.2.2, < 6.4.0.12≥ 6.5.0, < 6.6.4+1 more2021-04-29
CVE-2021-1501 [HIGH] CWE-613 CVE-2021-1501: A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition.The vulnerability is due to a crash that occurs during a has
nvd
Cisco Firepower Threat Defense vulnerabilities | cvebase