cbcvebase.

Cisco Firepower Threat Defense vulnerabilities

237 known vulnerabilities affecting cisco/firepower_threat_defense.

Total CVEs
237
CISA KEV
11
actively exploited
Public exploits
9
Exploited in wild
10
Severity breakdown
CRITICAL6HIGH126MEDIUM92LOW1UNKNOWN12

Vulnerabilities

Page 9 of 12
CVE-2020-3255HIGHCVSS 7.5≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+1 more2020-05-06
CVE-2020-3255 [HIGH] CWE-400 CVE-2020-3255: A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Softw A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a high rate of IPv4
nvdcisco
CVE-2020-3254HIGHCVSS 7.5≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+1 more2020-05-06
CVE-2020-3254 [HIGH] CWE-400 CVE-2020-3254: Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Ad Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory mana
nvd
CVE-2020-3298HIGHCVSS 7.5≥ 6.2.0, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-05-06
CVE-2020-3298 [HIGH] CWE-125 CVE-2020-3298: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memor
nvd
CVE-2020-3196HIGHCVSS 8.6≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-05-06
CVE-2020-3196 [HIGH] CWE-400 CVE-2020-3196: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Ad A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of service (DoS) condition. The vulnerabilit
nvd
CVE-2020-3253MEDIUMCVSS 6.7fixed in 6.5.02020-05-06
CVE-2020-3253 [MEDIUM] CWE-284 CVE-2020-3253: A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by enab
nvdcisco
CVE-2020-3188MEDIUMCVSS 5.3≥ 6.4.0, < 6.4.0.9≥ 6.5.0, < 6.5.0.52020-05-06
CVE-2020-3188 [MEDIUM] CWE-399 CVE-2020-3188: A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for ma A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition. The vulnerability exists because the default sessi
nvdcisco
CVE-2020-3308MEDIUMCVSS 4.9fixed in 6.2.2.12020-05-06
CVE-2020-3308 [MEDIUM] CWE-347 CVE-2020-3308: A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker
nvdcisco
CVE-2020-3186MEDIUMCVSS 5.3≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.7+1 more2020-05-06
CVE-2020-3186 [MEDIUM] CWE-284 CVE-2020-3186: A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access l
nvdcisco
CVE-2020-3315MEDIUMCVSS 5.3fixed in 6.6.02020-05-06
CVE-2020-3315 [MEDIUM] CWE-693 CVE-2020-3315: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker could exploit this vulnerability by se
nvd
CVE-2020-3285MEDIUMCVSS 5.8≥ 6.4.0, ≤ 6.4.0.82020-05-06
CVE-2020-3285 [MEDIUM] CWE-693 CVE-2020-3285: A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category funct A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3 policy to block traffic for a specific URL. The vulnerability is due to a logic error with Snort handling of the co
nvdcisco
CVE-2020-3167HIGHCVSS 7.8≥ 6.2.2, < 6.2.3.13≥ 6.3.0, < 6.4.0.8+1 more2020-02-26
CVE-2020-3167 [HIGH] CWE-78 CVE-2020-3167: A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an auth A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A
nvd
CVE-2020-3166MEDIUMCVSS 6.7≥ 6.2.2, < 6.2.3.16≥ 6.3.0, < 6.5.0.32020-02-26
CVE-2020-3166 [MEDIUM] CWE-20 CVE-2020-3166: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to re A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to a specific CLI command. A successful exploit co
nvd
CVE-2019-12673HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.42019-10-02
CVE-2019-12673 [HIGH] CWE-119 CVE-2019-12673: A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Fir A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of FTP data. An attacker could exploit this vuln
nvd
CVE-2019-15256HIGHCVSS 8.6≥ 6.2.0, < 6.2.3.11≥ 6.3.0, < 6.3.0.22019-10-02
CVE-2019-15256 [HIGH] CWE-399 CVE-2019-15256: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper ma
nvd
CVE-2019-12678HIGHCVSS 7.5fixed in 6.2.3.15≥ 6.3.0, < 6.3.0.4+1 more2019-10-02
CVE-2019-12678 [HIGH] CWE-191 CVE-2019-12678: A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Securit A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper parsing of SIP messages
nvd
CVE-2019-12674HIGHCVSS 8.2fixed in 6.4.0.22019-10-02
CVE-2019-12674 [HIGH] CWE-216 CVE-2019-12674: Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Softw Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An a
nvdcisco
CVE-2019-12699HIGHCVSS 7.8≤ 6.1.0≥ 6.2.0, < 6.2.3.14+1 more2019-10-02
CVE-2019-12699 [HIGH] CWE-20 CVE-2019-12699: Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by incl
nvd
CVE-2019-12675HIGHCVSS 8.8fixed in 6.4.0.22019-10-02
CVE-2019-12675 [HIGH] CWE-216 CVE-2019-12675: Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Softw Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An a
nvdcisco
CVE-2019-12676HIGHCVSS 7.4fixed in 6.3.0.4≥ 6.4.0, < 6.4.0.42019-10-02
CVE-2019-12676 [HIGH] CWE-20 CVE-2019-12676: A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security App A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the affe
nvd
CVE-2019-12698HIGHCVSS 7.5fixed in 6.2.3.15≥ 6.3.0, < 6.3.0.5+1 more2019-10-02
CVE-2019-12698 [HIGH] CWE-400 CVE-2019-12698: A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for a specific WebVPN HTTP page request. An attacker c
nvd