cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

225 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
225
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
16
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1

Vulnerabilities

Page 8 of 12
CVE-2022-20934P3MEDIUMCVSS 6.7≥ 6.1.0, ≤ 6.1.0.7≥ 6.2.0, ≤ 6.2.0.6+22 more2022-11-15
CVE-2022-20934 [MEDIUM] CWE-77 CVE-2022-20934: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by inje
nvd
CVE-2020-3299P3MEDIUMCVSS 5.8≥ 6.0.0, < 6.3.0.12020-10-21
CVE-2020-3299 [MEDIUM] CWE-693 CVE-2020-3299: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. The vulnerability is due to incorrect detection of modified HTTP packets used in chunked responses. An attacker could exploit this vulnerability by sending crafted HTTP
nvd
CVE-2023-20256P3MEDIUMCVSS 5.8v6.2.3.16v6.2.3.17+41 more2023-11-01
CVE-2023-20256 [MEDIUM] CWE-290 CVE-2023-20256: Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. These vulnerabilit
nvd
CVE-2023-20071P3MEDIUMCVSS 5.8fixed in 6.4.0.17≥ 6.5.0, < 7.0.6+5 more2023-11-01
CVE-2023-20071 [MEDIUM] CWE-1039 CVE-2023-20071: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP t
nvd
CVE-2024-20299P3MEDIUMCVSS 5.8v6.2.3v6.2.3.1+71 more2024-10-23
CVE-2024-20299 [MEDIUM] CWE-290 CVE-2024-20299: A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due
nvd
CVE-2024-20297P3MEDIUMCVSS 5.8v6.2.3v6.2.3.1+78 more2024-10-23
CVE-2024-20297 [MEDIUM] CWE-290 CVE-2024-20297: A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due
nvd
CVE-2024-20407P3MEDIUMCVSS 5.8v6.2.3v6.2.3.1+88 more2024-10-23
CVE-2024-20407 [MEDIUM] CWE-399 CVE-2024-20407: A vulnerability in the interaction between the TCP Intercept feature and the Snort 3 detection engin A vulnerability in the interaction between the TCP Intercept feature and the Snort 3 detection engine on Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies on an affected system. Devices that are configured with Snort 2 are not affected by this vulnerability. This vulnerability
nvd
CVE-2020-3577P4HIGHCVSS 7.4fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3577 [HIGH] CWE-20 CVE-2020-3577: A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Softwa A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces that are configured either as Inline Pair or in Passive mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation when Ethernet frames are proc
nvd
CVE-2020-3334P4HIGHCVSS 7.4fixed in 6.6.02020-05-06
CVE-2020-3334 [HIGH] CWE-399 CVE-2020-3334: A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition on an affected dev
nvd
CVE-2021-40125P4MEDIUMCVSS 6.5fixed in 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-40125 [MEDIUM] CWE-416 CVE-2021-40125: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Secu A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. This vulnerability is due to improper control of a reso
nvd
CVE-2020-3457P4MEDIUMCVSS 6.7≥ 6.2.2, < 6.3.0.6≥ 6.4.0, < 6.4.0.9+1 more2020-10-21
CVE-2020-3457 [MEDIUM] CWE-78 CVE-2020-3457: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to in A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted
nvd
CVE-2022-20927P4MEDIUMCVSS 6.5≥ 6.5.0, ≤ 6.5.0.5≥ 6.7.0, ≤ 6.7.0.3+7 more2022-11-15
CVE-2022-20927 [MEDIUM] CWE-120 CVE-2022-20927: A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a device initiates SSL/TLS connection
nvd
CVE-2021-1236P4MEDIUMCVSS 5.3fixed in 6.5.0.52021-01-13
CVE-2021-1236 [MEDIUM] CWE-670 CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine th Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would
nvd
CVE-2022-20928P4MEDIUMCVSS 5.8v6.1.0v6.1.0.1+85 more2022-11-15
CVE-2022-20928 [MEDIUM] CWE-863 CVE-2022-20928: A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user. This vulnerability is due to a flaw in the authorization verifications during t
nvd
CVE-2023-20245P4MEDIUMCVSS 5.8v6.2.3.3v6.2.3.4+66 more2023-11-01
CVE-2023-20245 [MEDIUM] CWE-290 CVE-2023-20245: Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. These vulnerabilit
nvd
CVE-2021-1495P4MEDIUMCVSS 5.3fixed in 6.4.0.12≥ 6.5.0, < 6.6.4+1 more2021-04-29
CVE-2021-1495 [MEDIUM] CWE-755 CVE-2021-1495: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through a
nvd
CVE-2024-20384P4MEDIUMCVSS 5.8v7.0.0v7.0.0.1+36 more2024-10-23
CVE-2024-20384 [MEDIUM] CWE-290 CVE-2024-20384: A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. This vulnerabilit
nvd
CVE-2024-20293P4MEDIUMCVSS 5.8≥ 7.3.0, ≤ 7.4.02024-05-22
CVE-2024-20293 [MEDIUM] CWE-436 CVE-2024-20293: A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Applian A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to a logic error that occ
nvd
CVE-2024-20261P4MEDIUMCVSS 5.8v6.2.3v6.2.3.1+71 more2024-05-22
CVE-2024-20261 [MEDIUM] CWE-284 CVE-2024-20261: A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive file. This vulnerability exists because of a logic error when a specific class of encrypted archive
nvd
CVE-2024-20363P4MEDIUMCVSS 5.8v7.4.02024-05-22
CVE-2024-20363 [MEDIUM] CWE-290 CVE-2024-20363: Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IP Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP
nvd
Cisco Firepower Threat Defense vulnerabilities | cvebase