cbcvebase.

Cisco Firepower Threat Defense Software vulnerabilities

31 known vulnerabilities affecting cisco/firepower_threat_defense_software.

Total CVEs
31
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH10MEDIUM21

Vulnerabilities

Page 1 of 2
CVE-2024-20481P2MEDIUMCVSS 5.8KEVv6.2.3v6.2.3.1+88 more2024-10-23
CVE-2024-20481 [MEDIUM] CWE-772 CVE-2024-20481: A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnera
nvd
CVE-2024-20342P3HIGHCVSS 8.6fixed in 7.0.6.2≥ 7.2.0, < 7.2.6+3 more2024-10-23
CVE-2024-20342 [HIGH] CWE-1025 CVE-2024-20342: Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort d Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic th
nvd
CVE-2026-20103P3HIGHCVSS 8.6≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20103 [HIGH] CWE-770 CVE-2026-20103: A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access SSL VPN connections. This does no
nvd
CVE-2026-20039P3HIGHCVSS 8.6≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.10+3 more2026-03-04
CVE-2026-20039 [HIGH] CWE-244 CVE-2026-20039: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Sof A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to ineffective memory management of the VPN web
nvd
CVE-2026-20101P3HIGHCVSS 8.6≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20101 [HIGH] CWE-330 CVE-2026-20101: A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software a A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could ex
nvd
CVE-2024-20426P3HIGHCVSS 8.6v7.2.0v7.2.0.1+19 more2024-10-23
CVE-2024-20426 [HIGH] CWE-476 CVE-2024-20426: A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient i
nvd
CVE-2026-20014P3HIGHCVSS 7.7≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20014 [HIGH] CWE-401 CVE-2026-20014: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to the imp
nvd
CVE-2026-20105P3HIGHCVSS 7.7≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20105 [HIGH] CWE-401 CVE-2026-20105: A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaust device memory resulting in a denial of service (DoS) condition.This does not affect the man
nvd
CVE-2026-20049P3HIGHCVSS 7.7≥ 7.2.0, < 7.2.11≥ 7.3.0, < 7.4.3+2 more2026-03-04
CVE-2026-20049 [HIGH] CWE-131 CVE-2026-20049: A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange versi A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affec
nvd
CVE-2024-20351P3HIGHCVSS 7.5v6.2.3v6.2.3.1+83 more2024-10-23
CVE-2024-20351 [HIGH] CWE-400 CVE-2024-20351: A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firep A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be dropped, resulting in a denial of service (DoS) condition. This vulnerability is due to the improp
nvd
CVE-2024-20339P3HIGHCVSS 7.5v6.2.3v6.2.3.1+78 more2024-10-23
CVE-2024-20339 [HIGH] CWE-476 CVE-2024-20339: A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for C A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an issue that occurs when TLS traffic is processed. An attacker could exploit th
nvd
CVE-2026-20016P3MEDIUMCVSS 6.7≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20016 [MEDIUM] CWE-88 CVE-2026-20016: A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Se A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the attacker must have valid administrative credentials on an aff
nvd
CVE-2024-20358P3MEDIUMCVSS 6.7v6.2.3v6.2.3.1+78 more2024-04-24
CVE-2024-20358 [MEDIUM] CWE-78 CVE-2024-20358: A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is availab A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. Administrator-level privileges are requ
nvd
CVE-2026-20050P3MEDIUMCVSS 6.8≥ 7.1.0, < 7.2.11≥ 7.3.0, < 7.4.4+2 more2026-03-04
CVE-2026-20050 [MEDIUM] CWE-404 CVE-2026-20050: A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secur A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management during the inspection of TLS 1.2 encr
nvd
CVE-2026-20013P3MEDIUMCVSS 5.8≥ 7.2.0, < 7.2.11≥ 7.3.0, < 7.4.3+2 more2026-03-04
CVE-2026-20013 [MEDIUM] CWE-401 CVE-2026-20013: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to memory exhaustion caused by not fre
nvd
CVE-2026-20015P3MEDIUMCVSS 5.8≥ 7.2.0, < 7.2.11≥ 7.3.0, < 7.4.3+2 more2026-03-04
CVE-2026-20015 [MEDIUM] CWE-401 CVE-2026-20015: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network. This vulnerability is due to a memory leak when parsing IKEv2 packets
nvd
CVE-2024-20485P3MEDIUMCVSS 6.7v6.2.3v6.2.3.1+88 more2024-10-23
CVE-2024-20485 [MEDIUM] CWE-94 CVE-2024-20485: A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper v
nvd
CVE-2026-20008P3MEDIUMCVSS 6.0≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20008 [MEDIUM] CWE-78 CVE-2026-20008: A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Se A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root. This vulnerability exists because use
nvd
CVE-2024-20331P3MEDIUMCVSS 5.9v6.2.3v6.2.3.1+82 more2024-10-23
CVE-2024-20331 [MEDIUM] CWE-330 CVE-2024-20331: A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent users from authenticating. This vulnerability is due to insufficient entropy in the authentic
nvd
CVE-2026-20022P4MEDIUMCVSS 6.5v6.4.0v6.4.0.1+74 more2026-03-04
CVE-2026-20022 [MEDIUM] CWE-823 CVE-2026-20022: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf canon. This vulnerability is due to
nvd
Cisco Firepower Threat Defense Software vulnerabilities | cvebase