cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

237 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
237
CISA KEV
11
actively exploited
Public exploits
9
Exploited in wild
10
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1UNKNOWN12

Vulnerabilities

Page 8 of 12
CVE-2020-3565MEDIUMCVSS 5.8fixed in 6.4.0.8≥ 6.5.0, < 6.5.0.4+1 more2020-10-21
CVE-2020-3565 [MEDIUM] CWE-284 CVE-2020-3565: A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices on an affected system. The vulnerability exists because TCP Intercept is invoked when the embryonic connection limit
nvdcisco
CVE-2020-3581MEDIUMCVSS 6.1fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3581 [MEDIUM] CWE-79 CVE-2020-3581: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3457MEDIUMCVSS 6.7≥ 6.2.2, < 6.3.0.6≥ 6.4.0, < 6.4.0.9+1 more2020-10-21
CVE-2020-3457 [MEDIUM] CWE-78 CVE-2020-3457: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to in A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted
nvd
CVE-2020-3583MEDIUMCVSS 6.1fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3583 [MEDIUM] CWE-79 CVE-2020-3583: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3458MEDIUMCVSS 6.7≤ 6.2.2≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3458 [MEDIUM] CWE-693 CVE-2020-3458: Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Softw Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass the secure boot mechanism. The vulnerabilities are due to insufficient protections
nvd
CVE-2020-3578MEDIUMCVSS 6.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3578 [MEDIUM] CWE-863 CVE-2020-3578: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked. The vulnerability is due to insufficient validation
nvd
CVE-2020-3299MEDIUMCVSS 5.8≥ 6.0.0, < 6.3.0.12020-10-21
CVE-2020-3299 [MEDIUM] CWE-693 CVE-2020-3299: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. The vulnerability is due to incorrect detection of modified HTTP packets used in chunked responses. An attacker could exploit this vulnerability by sending crafted HTTP
nvd
CVE-2020-3585LOWCVSS 3.7fixed in 6.4.0.10≥ 6.5.0, < 6.5.0.5+1 more2020-10-21
CVE-2020-3585 [LOW] CWE-203 CVE-2020-3585: A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper implementation of countermeasures against the Bleic
nvd
CVE-2020-3452HIGHCVSS 7.5KEVPoC≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+3 more2020-07-22
CVE-2020-3452 [HIGH] CWE-20 CVE-2020-3452: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in H
nvd
CVE-2020-3187CRITICALCVSS 9.1PoC≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-05-06
CVE-2020-3187 [CRITICAL] CWE-22 CVE-2020-3187: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of prop
nvd
CVE-2020-3179HIGHCVSS 7.5≥ 6.3.0, < 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3179 [HIGH] CWE-415 CVE-2020-3179: A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Fir A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory handling error when GRE over IPv6 traffic is processed. An attack
nvdcisco
CVE-2020-3195HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.9≥ 6.5.0, < 6.5.0.52020-05-06
CVE-2020-3195 [HIGH] CWE-400 CVE-2020-3195: A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security App A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to incorrect processing of certain OSPF packets. An attacker cou
nvd
CVE-2020-3334HIGHCVSS 7.4fixed in 6.6.02020-05-06
CVE-2020-3334 [HIGH] CWE-399 CVE-2020-3334: A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition on an affected dev
nvd
CVE-2020-3306HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.42020-05-06
CVE-2020-3306 [HIGH] CWE-400 CVE-2020-3306: A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incorrect processing of certain DHCP packets. An attacker could exploit t
nvd
CVE-2020-3189HIGHCVSS 8.6v6.2.3.12v6.2.3.13+2 more2020-05-06
CVE-2020-3189 [HIGH] CWE-400 CVE-2020-3189: A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Sof A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behaviors or device crashes. The vulnerability is due to the system memory not being properly freed fo
nvdcisco
CVE-2020-3303HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3303 [HIGH] CWE-399 CVE-2020-3303: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could expl
nvd
CVE-2020-3191HIGHCVSS 8.6≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+1 more2020-05-06
CVE-2020-3191 [HIGH] CWE-20 CVE-2020-3191: A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Softw A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper length validation of a field
nvd
CVE-2020-3259HIGHCVSS 7.5KEV≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-05-06
CVE-2020-3259 [HIGH] CWE-200 CVE-2020-3259: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer trackin
nvd
CVE-2020-3283HIGHCVSS 8.6≥ 6.4.0, < 6.4.0.92020-05-06
CVE-2020-3283 [HIGH] CWE-119 CVE-2020-3283: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Fi A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communicatio
nvd
CVE-2020-3305HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3305 [HIGH] CWE-400 CVE-2020-3305: A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP packets. An at
nvd
Cisco Firepower Threat Defense vulnerabilities | cvebase