cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

225 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
225
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
16
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1

Vulnerabilities

Page 7 of 12
CVE-2020-3306P3HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.42020-05-06
CVE-2020-3306 [HIGH] CWE-400 CVE-2020-3306: A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incorrect processing of certain DHCP packets. An attacker could exploit t
nvd
CVE-2020-3305P3HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3305 [HIGH] CWE-400 CVE-2020-3305: A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP packets. An at
nvd
CVE-2020-3317P3HIGHCVSS 7.5fixed in 6.4.0.10≥ 6.5.0, < 6.5.0.52020-10-21
CVE-2020-3317 [HIGH] CWE-20 CVE-2020-3317: A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software cou A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component. An attacker could exploit this vulnerability by sending a malformed TLS packet through a Cisco
nvd
CVE-2022-20946P3HIGHCVSS 7.5≥ 6.3.0, ≤ 6.3.0.5≥ 6.4.0, ≤ 6.4.0.15+7 more2022-11-15
CVE-2022-20946 [HIGH] CWE-122 CVE-2022-20946: A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Fir A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory handling error that occurs when GRE traffic is processed. An a
nvd
CVE-2022-20854P3HIGHCVSS 7.5≥ 6.1.0, ≤ 6.1.0.7≥ 6.2.0, ≤ 6.2.0.6+23 more2022-11-15
CVE-2022-20854 [HIGH] CWE-400 CVE-2022-20854: A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when an SSH session fails to be establi
nvd
CVE-2019-12674P3HIGHCVSS 8.2fixed in 6.4.0.22019-10-02
CVE-2019-12674 [HIGH] CWE-216 CVE-2019-12674: Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Softw Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An a
nvd
CVE-2018-0453P3HIGHCVSS 8.2v5.4.0v6.0.0+5 more2018-10-05
CVE-2018-0453 [HIGH] CWE-264 CVE-2018-0453: A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with root privileges on the Cisco Firepower Management Center (FMC), or through Cisco FMC on other Firepower sensors and
nvd
CVE-2020-3303P3HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3303 [HIGH] CWE-399 CVE-2020-3303: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could expl
nvd
CVE-2020-3578P3MEDIUMCVSS 6.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3578 [MEDIUM] CWE-863 CVE-2020-3578: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked. The vulnerability is due to insufficient validation
nvd
CVE-2021-1493P3HIGHCVSS 7.1fixed in 6.4.0.12≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1493 [HIGH] CWE-120 CVE-2021-1493: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to insufficient boundary checks for specific data that is provided to the web services
nvd
CVE-2017-6625P3HIGHCVSS 7.1v6.0.0v6.0.1+5 more2017-05-03
CVE-2017-6625 [HIGH] CWE-399 CVE-2017-6625: A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access control policy of Cisco Firepower System Software could allow an authenticated, remote attacker to cause an affected system to stop inspecting and processing packets, resulting in a denial of service (DoS) condition. Th
nvd
CVE-2026-20073P3MEDIUMCVSS 5.8v6.4.0v6.4.0.1+72 more2026-03-04
CVE-2026-20073 [MEDIUM] CWE-284 CVE-2026-20073: A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be denied through an affected device. This vulnerability is due to improper error handling when an affected device that is joining a c
nvd
CVE-2019-1696P3HIGHCVSS 7.4≥ 6.0.0, < 6.2.3.122019-05-03
CVE-2019-1696 [HIGH] CWE-400 CVE-2019-1696: Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine fo Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2018-15399P3MEDIUMCVSS 6.8v6.2.02018-10-05
CVE-2018-15399 [MEDIUM] CWE-400 CVE-2018-15399: A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cis A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing boundary check i
nvd
CVE-2021-1476P3MEDIUMCVSS 6.7≥ 6.5.0, < 6.6.4≥ 6.7.0, < 6.7.0.22021-04-29
CVE-2021-1476 [MEDIUM] CWE-78 CVE-2021-1476: A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower T A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient input validation of commands that are supplied
nvd
CVE-2022-20922P3MEDIUMCVSS 6.5v7.1.0v7.1.0.1+3 more2022-11-15
CVE-2022-20922 [MEDIUM] CWE-244 CVE-2022-20922: Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detecti Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to improper management of system r
nvd
CVE-2019-12676P3HIGHCVSS 7.4fixed in 6.3.0.4≥ 6.4.0, < 6.4.0.42019-10-02
CVE-2019-12676 [HIGH] CWE-20 CVE-2019-12676: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the affe
nvd
CVE-2019-1693P3MEDIUMCVSS 6.5≥ 6.2.1, < 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1693 [MEDIUM] CWE-399 CVE-2019-1693: A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper management of authenticated sessions in the WebVPN portal. An a
nvd
CVE-2019-12700P3MEDIUMCVSS 6.5≤ 6.1.0≥ 6.2.0, < 6.2.3.14+2 more2019-10-02
CVE-2019-12700 [MEDIUM] CWE-400 CVE-2019-12700: A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Fire A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper resource ma
nvd
CVE-2022-20924P3MEDIUMCVSS 6.5v6.6.0v6.6.0.1+22 more2022-11-15
CVE-2022-20924 [MEDIUM] CWE-703 CVE-2022-20924: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An
nvd