Cisco Secure Firewall Threat Defense vulnerabilities
269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.
Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1
Vulnerabilities
Page 11 of 14
CVE-2018-15390P4MEDIUMCVSS 6.8≥ 6.2.3.0, ≤ 6.2.3.42018-10-05
CVE-2018-15390 [MEDIUM] CWE-399 CVE-2018-15390: A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could
A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to release spinlocks when a device is running low on system
nvd
CVE-2019-12694P4MEDIUMCVSS 6.7fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.42019-10-02
CVE-2019-12694 [MEDIUM] CWE-20 CVE-2019-12694: A vulnerability in the command line interface (CLI) of Cisco Firepower Threat Defense (FTD) Software
A vulnerability in the command line interface (CLI) of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker with administrative privileges to execute commands on the underlying operating system with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerab
nvd
CVE-2022-20826P4MEDIUMCVSS 6.8v7.1.0.0v7.2.0.0+1 more2022-11-15
CVE-2022-20826 [MEDIUM] CWE-501 CVE-2022-20826: A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are run
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality.
This vulnerability is due to a l
nvd
CVE-2020-3514P4MEDIUMCVSS 6.7≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3514 [MEDIUM] CWE-216 CVE-2020-3514: A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could
A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their Cisco FTD instance and execute commands with root privileges in the host namespace. The attacker must have valid credentials on the device.The vulnerability exists because a confi
nvd
CVE-2021-1488P4MEDIUMCVSS 6.7≥ 6.5.0, < 6.6.4≥ 6.7.0, < 6.7.0.22021-04-29
CVE-2021-1488 [MEDIUM] CWE-77 CVE-2021-1488: A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco
A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS). This vulnerability is due to insufficient input validation. An a
nvd
CVE-2019-1695P4MEDIUMCVSS 6.5≥ 6.2.1, < 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1695 [MEDIUM] CWE-284 CVE-2019-1695: A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisc
A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected d
nvd
CVE-2022-20713P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+69 more2022-08-10
CVE-2022-20713 [MEDIUM] CWE-444 CVE-2022-20713: A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA)
A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of input that is passed to
nvd
CVE-2026-20022P4MEDIUMCVSS 6.5v6.4.0v6.4.0.1+74 more2026-03-04
CVE-2026-20022 [MEDIUM] CWE-823 CVE-2026-20022: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf canon.
This vulnerability is due to
nvd
CVE-2018-0297P4MEDIUMCVSS 5.8v6.0.0v6.1.0+2 more2018-05-17
CVE-2018-0297 [MEDIUM] CWE-693 CVE-2018-0297: A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an un
A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to the incorrect handling of TCP SSL packets received out of order. An attacker could exploit this
nvd
CVE-2018-0243P4MEDIUMCVSS 5.8fixed in 6.2.32018-04-19
CVE-2018-0243 [MEDIUM] CWE-693 CVE-2018-0243: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy that is intended to drop the Server Message Block Version 2 (SMB2) and SMB Version 3 (SMB3) protocols if malware is detected. The vulnerability is due to incorrect detection of an SMB2 or
nvd
CVE-2018-0244P4MEDIUMCVSS 5.8fixed in 6.2.32018-04-19
CVE-2018-0244 [MEDIUM] CWE-693 CVE-2018-0244: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy to drop the Server Message Block (SMB) protocol if a malware file is detected. The vulnerability is due to how the SMB protocol handles a case in which a large file transfer fails. This ca
nvd
CVE-2020-3565P4MEDIUMCVSS 5.8fixed in 6.4.0.8≥ 6.5.0, < 6.5.0.4+1 more2020-10-21
CVE-2020-3565 [MEDIUM] CWE-284 CVE-2020-3565: A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software
A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices on an affected system. The vulnerability exists because TCP Intercept is invoked when the embryonic connection limit
nvd
CVE-2020-3564P4MEDIUMCVSS 5.3fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3564 [MEDIUM] CWE-284 CVE-2020-3564: A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection. The vulnerability is due to ineffective flow tracking of FTP traffic. An attacker could exploit this vulnerability by sending crafte
nvd
CVE-2020-3186P4MEDIUMCVSS 5.3≥ 6.3.0, < 6.3.0.6≥ 6.4.0, < 6.4.0.7+1 more2020-05-06
CVE-2020-3186 [MEDIUM] CWE-284 CVE-2020-3186: A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD)
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access l
nvd
CVE-2021-34753P4MEDIUMCVSS 5.3fixed in 6.4.0.13≥ 6.5.0, < 6.6.5.1+2 more2024-11-15
CVE-2021-34753 [MEDIUM] CWE-284 CVE-2021-34753: A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco
A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic.
This vulnerability is due to incomplete processing during deep packet inspection for ENIP packets. An attacker could e
nvd
CVE-2020-3458P4MEDIUMCVSS 6.7≤ 6.2.2≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3458 [MEDIUM] CWE-693 CVE-2020-3458: Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Softw
Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass the secure boot mechanism. The vulnerabilities are due to insufficient protections
nvd
CVE-2020-3253P4MEDIUMCVSS 6.7fixed in 6.5.02020-05-06
CVE-2020-3253 [MEDIUM] CWE-284 CVE-2020-3253: A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could
A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by enab
nvd
CVE-2019-1691P4MEDIUMCVSS 5.8fixed in 6.2.3.42019-02-21
CVE-2019-1691 [MEDIUM] CWE-20 CVE-2019-1691: A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an un
A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT detection engine, resulting in a denial of service (DoS) condition. The vulnerability is due to the incomplete error handling of the SSL or TLS packet header during the connectio
nvd
CVE-2024-20341P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+82 more2024-10-23
CVE-2024-20341 [MEDIUM] CWE-80 CVE-2024-20341: A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) So
A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper valida
nvd
CVE-2024-20382P4MEDIUMCVSS 6.1v6.2.3.1v6.2.3.2+88 more2024-10-23
CVE-2024-20382 [MEDIUM] CWE-80 CVE-2024-20382: A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) So
A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper valida
nvd