cbcvebase.

Cisco Secure Firewall Threat Defense vulnerabilities

269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.

Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1

Vulnerabilities

Page 10 of 14
CVE-2021-1236P4MEDIUMCVSS 5.3fixed in 6.5.0.52021-01-13
CVE-2021-1236 [MEDIUM] CWE-670 CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine th Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would
nvd
CVE-2022-20928P4MEDIUMCVSS 5.8v6.1.0v6.1.0.1+85 more2022-11-15
CVE-2022-20928 [MEDIUM] CWE-863 CVE-2022-20928: A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user. This vulnerability is due to a flaw in the authorization verifications during t
nvd
CVE-2023-20071P3MEDIUMCVSS 5.8fixed in 6.4.0.17≥ 6.5.0, < 7.0.6+5 more2023-11-01
CVE-2023-20071 [MEDIUM] CWE-1039 CVE-2023-20071: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP t
nvd
CVE-2023-20245P4MEDIUMCVSS 5.8v6.2.3.3v6.2.3.4+66 more2023-11-01
CVE-2023-20245 [MEDIUM] CWE-290 CVE-2023-20245: Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. These vulnerabilit
nvd
CVE-2021-1495P4MEDIUMCVSS 5.3fixed in 6.4.0.12≥ 6.5.0, < 6.6.4+1 more2021-04-29
CVE-2021-1495 [MEDIUM] CWE-755 CVE-2021-1495: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through a
nvd
CVE-2024-20384P4MEDIUMCVSS 5.8v7.0.0v7.0.0.1+36 more2024-10-23
CVE-2024-20384 [MEDIUM] CWE-290 CVE-2024-20384: A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. This vulnerabilit
nvd
CVE-2026-20057P4MEDIUMCVSS 5.8v7.2.0v7.2.0.1+35 more2026-03-04
CVE-2026-20057 [MEDIUM] CWE-369 CVE-2026-20057: Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to lack of proper error checking when decompressing VBA data. An attacker could exploit this vulnerability
nvd
CVE-2024-20293P4MEDIUMCVSS 5.8≥ 7.3.0, ≤ 7.4.02024-05-22
CVE-2024-20293 [MEDIUM] CWE-436 CVE-2024-20293: A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Applian A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to a logic error that occ
nvd
CVE-2026-20006P4MEDIUMCVSS 5.8v7.2.0v7.2.0.1+31 more2026-03-04
CVE-2026-20006 [MEDIUM] CWE-388 CVE-2026-20006: A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secur A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper implementa
nvd
CVE-2024-20261P4MEDIUMCVSS 5.8v6.2.3v6.2.3.1+71 more2024-05-22
CVE-2024-20261 [MEDIUM] CWE-284 CVE-2024-20261: A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive file. This vulnerability exists because of a logic error when a specific class of encrypted archive
nvd
CVE-2024-20363P4MEDIUMCVSS 5.8v7.4.02024-05-22
CVE-2024-20363 [MEDIUM] CWE-290 CVE-2024-20363: Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IP Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP
nvd
CVE-2020-3166P4MEDIUMCVSS 6.7≥ 6.2.2, < 6.2.3.16≥ 6.3.0, < 6.5.0.32020-02-26
CVE-2020-3166 [MEDIUM] CWE-20 CVE-2020-3166: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to re A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to a specific CLI command. A successful exploit co
nvd
CVE-2020-3285P4MEDIUMCVSS 5.8≥ 6.4.0, ≤ 6.4.0.82020-05-06
CVE-2020-3285 [MEDIUM] CWE-693 CVE-2020-3285: A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category funct A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3 policy to block traffic for a specific URL. The vulnerability is due to a logic error with Snort handling of the co
nvd
CVE-2026-20070P4MEDIUMCVSS 6.1v6.4.0v6.4.0.1+73 more2026-03-04
CVE-2026-20070 [MEDIUM] CWE-80 CVE-2026-20070: A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due
nvd
CVE-2020-3315P4MEDIUMCVSS 5.3fixed in 6.6.02020-05-06
CVE-2020-3315 [MEDIUM] CWE-693 CVE-2020-3315: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker could exploit this vulnerability by se
nvd
CVE-2021-1224P4MEDIUMCVSS 5.3fixed in 6.7.02021-01-13
CVE-2021-1224 [MEDIUM] CWE-693 CVE-2021-1224: Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjun Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the
nvd
CVE-2026-20052P4MEDIUMCVSS 5.8v7.4.0v7.4.1+4 more2026-03-04
CVE-2026-20052 [MEDIUM] CWE-788 CVE-2026-20052: A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure F A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a logic error in memory management when a device is performing Snort 3 SSL packet ins
nvd
CVE-2024-20431P4MEDIUMCVSS 5.8v7.0.0v7.0.0.1+30 more2024-10-23
CVE-2024-20431 [MEDIUM] CWE-229 CVE-2024-20431: A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) So A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation data. An attacker could exploit this vulnerability by sending traffic through an affected device
nvd
CVE-2017-3822P4MEDIUMCVSS 5.3v6.1.02017-02-03
CVE-2017-3822 [MEDIUM] CWE-20 CVE-2017-3822: A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Devic A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, remote attacker to add arbitrary entries to the audit log. This vulnerability affects Cisco Firepower Threat Defense Software versions 6.1.x on the following vulnerable products that have enabled FDM: ASA55
nvd
CVE-2024-20388P4MEDIUMCVSS 5.3v6.4.0.4v6.4.0.10+11 more2024-10-23
CVE-2024-20388 [MEDIUM] CWE-202 CVE-2024-20388: A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software c A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password r
nvd