Cisco Firepower Threat Defense vulnerabilities
225 known vulnerabilities affecting cisco/firepower_threat_defense.
Total CVEs
225
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
16
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1
Vulnerabilities
Page 9 of 12
CVE-2020-3166P4MEDIUMCVSS 6.7≥ 6.2.2, < 6.2.3.16≥ 6.3.0, < 6.5.0.32020-02-26
CVE-2020-3166 [MEDIUM] CWE-20 CVE-2020-3166: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to re
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to a specific CLI command. A successful exploit co
nvd
CVE-2020-3285P4MEDIUMCVSS 5.8≥ 6.4.0, ≤ 6.4.0.82020-05-06
CVE-2020-3285 [MEDIUM] CWE-693 CVE-2020-3285: A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category funct
A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3 policy to block traffic for a specific URL. The vulnerability is due to a logic error with Snort handling of the co
nvd
CVE-2018-0244P4MEDIUMCVSS 5.8fixed in 6.2.32018-04-19
CVE-2018-0244 [MEDIUM] CWE-693 CVE-2018-0244: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy to drop the Server Message Block (SMB) protocol if a malware file is detected. The vulnerability is due to how the SMB protocol handles a case in which a large file transfer fails. This ca
nvd
CVE-2026-20070P4MEDIUMCVSS 6.1v6.4.0v6.4.0.1+73 more2026-03-04
CVE-2026-20070 [MEDIUM] CWE-80 CVE-2026-20070: A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device.
This vulnerability is due
nvd
CVE-2020-3315P4MEDIUMCVSS 5.3fixed in 6.6.02020-05-06
CVE-2020-3315 [MEDIUM] CWE-693 CVE-2020-3315: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker could exploit this vulnerability by se
nvd
CVE-2021-1224P4MEDIUMCVSS 5.3fixed in 6.7.02021-01-13
CVE-2021-1224 [MEDIUM] CWE-693 CVE-2021-1224: Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjun
Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the
nvd
CVE-2024-20431P4MEDIUMCVSS 5.8v7.0.0v7.0.0.1+30 more2024-10-23
CVE-2024-20431 [MEDIUM] CWE-229 CVE-2024-20431: A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) So
A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy.
This vulnerability is due to improper assignment of geolocation data. An attacker could exploit this vulnerability by sending traffic through an affected device
nvd
CVE-2017-3822P4MEDIUMCVSS 5.3v6.1.02017-02-03
CVE-2017-3822 [MEDIUM] CWE-20 CVE-2017-3822: A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Devic
A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, remote attacker to add arbitrary entries to the audit log. This vulnerability affects Cisco Firepower Threat Defense Software versions 6.1.x on the following vulnerable products that have enabled FDM: ASA55
nvd
CVE-2024-20388P4MEDIUMCVSS 5.3v6.4.0.4v6.4.0.10+11 more2024-10-23
CVE-2024-20388 [MEDIUM] CWE-202 CVE-2024-20388: A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software c
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device.
This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password r
nvd
CVE-2018-15390P4MEDIUMCVSS 6.8≥ 6.2.3.0, ≤ 6.2.3.42018-10-05
CVE-2018-15390 [MEDIUM] CWE-399 CVE-2018-15390: A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could
A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to release spinlocks when a device is running low on system
nvd
CVE-2022-20826P4MEDIUMCVSS 6.8v7.1.0.0v7.2.0.0+1 more2022-11-15
CVE-2022-20826 [MEDIUM] CWE-501 CVE-2022-20826: A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are run
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality.
This vulnerability is due to a l
nvd
CVE-2020-3514P4MEDIUMCVSS 6.7≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3514 [MEDIUM] CWE-216 CVE-2020-3514: A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could
A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their Cisco FTD instance and execute commands with root privileges in the host namespace. The attacker must have valid credentials on the device.The vulnerability exists because a confi
nvd
CVE-2021-1488P4MEDIUMCVSS 6.7≥ 6.5.0, < 6.6.4≥ 6.7.0, < 6.7.0.22021-04-29
CVE-2021-1488 [MEDIUM] CWE-77 CVE-2021-1488: A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco
A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS). This vulnerability is due to insufficient input validation. An a
nvd
CVE-2019-1695P4MEDIUMCVSS 6.5≥ 6.2.1, < 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1695 [MEDIUM] CWE-284 CVE-2019-1695: A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisc
A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected d
nvd
CVE-2019-1691P4MEDIUMCVSS 5.8fixed in 6.2.3.42019-02-21
CVE-2019-1691 [MEDIUM] CWE-20 CVE-2019-1691: A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an un
A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT detection engine, resulting in a denial of service (DoS) condition. The vulnerability is due to the incomplete error handling of the SSL or TLS packet header during the connectio
nvd
CVE-2018-0297P4MEDIUMCVSS 5.8v6.0.0v6.1.0+2 more2018-05-17
CVE-2018-0297 [MEDIUM] CWE-693 CVE-2018-0297: A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an un
A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to the incorrect handling of TCP SSL packets received out of order. An attacker could exploit this
nvd
CVE-2018-0243P4MEDIUMCVSS 5.8fixed in 6.2.32018-04-19
CVE-2018-0243 [MEDIUM] CWE-693 CVE-2018-0243: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy that is intended to drop the Server Message Block Version 2 (SMB2) and SMB Version 3 (SMB3) protocols if malware is detected. The vulnerability is due to incorrect detection of an SMB2 or
nvd
CVE-2020-3565P4MEDIUMCVSS 5.8fixed in 6.4.0.8≥ 6.5.0, < 6.5.0.4+1 more2020-10-21
CVE-2020-3565 [MEDIUM] CWE-284 CVE-2020-3565: A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software
A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices on an affected system. The vulnerability exists because TCP Intercept is invoked when the embryonic connection limit
nvd
CVE-2020-3564P4MEDIUMCVSS 5.3fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3564 [MEDIUM] CWE-284 CVE-2020-3564: A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection. The vulnerability is due to ineffective flow tracking of FTP traffic. An attacker could exploit this vulnerability by sending crafte
nvd
CVE-2020-3186P4MEDIUMCVSS 5.3≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.7+1 more2020-05-06
CVE-2020-3186 [MEDIUM] CWE-284 CVE-2020-3186: A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD)
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access l
nvd