Cisco Firepower Threat Defense vulnerabilities
237 known vulnerabilities affecting cisco/firepower_threat_defense.
Total CVEs
237
CISA KEV
11
actively exploited
Public exploits
9
Exploited in wild
10
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1UNKNOWN12
Vulnerabilities
Page 7 of 12
CVE-2020-3304HIGHCVSS 8.6fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3304 [HIGH] CWE-400 CVE-2020-3304: A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepow
A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP re
nvd
CVE-2020-3533HIGHCVSS 7.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3533 [HIGH] CWE-400 CVE-2020-3533: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Fir
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly. The vulnerability is due to a lack of sufficient memory management protections under heavy SNMP polling loads. An att
nvdcisco
CVE-2020-3529HIGHCVSS 7.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3529 [HIGH] CWE-400 CVE-2020-3529: A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Softw
A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to inefficient direct memory access (
nvd
CVE-2020-3562HIGHCVSS 8.6v6.3.0v6.4.0+1 more2020-10-21
CVE-2020-3562 [HIGH] CWE-119 CVE-2020-3562: A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco
A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation for certain fields of specific SSL/TLS messages. An
nvd
CVE-2020-3572HIGHCVSS 8.6fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+1 more2020-10-21
CVE-2020-3572 [HIGH] CWE-400 CVE-2020-3572: A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software a
A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak when closing SSL/TLS connections in a specific s
nvd
CVE-2020-3317HIGHCVSS 7.5fixed in 6.4.0.10≥ 6.5.0, < 6.5.0.52020-10-21
CVE-2020-3317 [HIGH] CWE-20 CVE-2020-3317: A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software cou
A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component. An attacker could exploit this vulnerability by sending a malformed TLS packet through a Cisco
nvdcisco
CVE-2020-3555HIGHCVSS 7.5≤ 6.2.2≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3555 [HIGH] CWE-404 CVE-2020-3555: A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a watchdog timeout and crash d
nvd
CVE-2020-3563HIGHCVSS 8.6≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.10+1 more2020-10-21
CVE-2020-3563 [HIGH] CWE-400 CVE-2020-3563: A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Softw
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a large number of TC
nvdcisco
CVE-2020-3436HIGHCVSS 8.6≤ 6.2.2≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3436 [HIGH] CWE-434 CVE-2020-3436: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco F
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload. The vulnerability exists because the affecte
nvd
CVE-2020-3554HIGHCVSS 7.5≤ 6.2.2≥ 6.3.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3554 [HIGH] CWE-400 CVE-2020-3554: A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory exhaustion condition. An attacker could exploit this vu
nvd
CVE-2020-3528HIGHCVSS 7.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3528 [HIGH] CWE-400 CVE-2020-3528: A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (
A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validatio
nvd
CVE-2020-3373HIGHCVSS 8.6v6.6.0.12020-10-21
CVE-2020-3373 [HIGH] CWE-400 CVE-2020-3373: A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA
A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. This memory leak could prevent traffic from being processed through the device, resulting in a denia
nvd
CVE-2020-3571HIGHCVSS 8.6≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.10+1 more2020-10-21
CVE-2020-3571 [HIGH] CWE-400 CVE-2020-3571: A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Softwa
A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incomplete input validation upon receiving ICMP packets. An attacker cou
nvd
CVE-2020-3550HIGHCVSS 8.1≤ 6.0.1≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3550 [HIGH] CWE-22 CVE-2020-3550: A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Fi
A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to perform directory traversal and access directories outside the restricted path. The vulnerability is due to insufficient input validation. An attacker could exploit this
nvd
CVE-2020-3582MEDIUMCVSS 6.1fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3582 [MEDIUM] CWE-79 CVE-2020-3582: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3564MEDIUMCVSS 5.3fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3564 [MEDIUM] CWE-284 CVE-2020-3564: A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection. The vulnerability is due to ineffective flow tracking of FTP traffic. An attacker could exploit this vulnerability by sending crafte
nvd
CVE-2020-3514MEDIUMCVSS 6.7≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3514 [MEDIUM] CWE-216 CVE-2020-3514: A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could
A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their Cisco FTD instance and execute commands with root privileges in the host namespace. The attacker must have valid credentials on the device.The vulnerability exists because a confi
nvdcisco
CVE-2020-3352MEDIUMCVSS 5.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3352 [MEDIUM] CWE-912 CVE-2020-3352: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacker could exploit this vulnerability by performing specific steps that make the hidden commands accessible. A succes
nvdcisco
CVE-2020-3561MEDIUMCVSS 4.7fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3561 [MEDIUM] CWE-93 CVE-2020-3561: A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Softwa
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the affected system. The vulnerability is due to improper input sanitization. An attacker could expl
nvd
CVE-2020-3580MEDIUMCVSS 6.1KEVPoCfixed in 6.4.0.12≥ 6.5.0, < 6.6.4+1 more2020-10-21
CVE-2020-3580 [MEDIUM] CWE-79 CVE-2020-3580: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd