cbcvebase.

Cisco Secure Firewall Threat Defense vulnerabilities

269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.

Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1

Vulnerabilities

Page 12 of 14
CVE-2023-20264P4MEDIUMCVSS 6.1v7.2.42023-11-01
CVE-2023-20264 [MEDIUM] CWE-601 CVE-2023-20264: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-o A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user who is authenticating to a re
nvd
CVE-2026-20102P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.9≥ 7.1.0, < 7.2.11+2 more2026-03-04
CVE-2026-20102 [MEDIUM] CWE-79 CVE-2026-20102: A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software a A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based information. This vulnerability is due t
nvd
CVE-2021-1256P4MEDIUMCVSS 6.0≤ 6.4.0≥ 6.6.0, < 6.6.42021-04-29
CVE-2021-1256 [MEDIUM] CWE-552 CVE-2021-1256: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques. A successful exploit could cause system instability if important system files are overwritten. This vulnerability is due to insuffi
nvd
CVE-2022-20943P4MEDIUMCVSS 5.8v7.0.0v7.0.0.1+2 more2022-11-15
CVE-2022-20943 [MEDIUM] CWE-244 CVE-2022-20943: Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detecti Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to improper management of system r
nvd
CVE-2021-34761P4MEDIUMCVSS 6.0≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34761 [MEDIUM] CWE-73 CVE-2021-34761: A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. A
nvd
CVE-2018-0254P4MEDIUMCVSS 5.3v6.1.0.5v6.2.0.2+2 more2018-04-19
CVE-2018-0254 [MEDIUM] CWE-693 CVE-2018-0254: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An atta
nvd
CVE-2018-0138P4MEDIUMCVSS 5.3v6.1.0v6.2.0+2 more2018-02-08
CVE-2018-0138 [MEDIUM] CWE-693 CVE-2018-0138: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file policies that are configured to block files transmitted to an affected device via the BitTorrent protocol. The vulnerability exists because the affected software does not detect BitTorrent handshake messages correct
nvd
CVE-2021-34787P4MEDIUMCVSS 5.3fixed in 6.4.0.13≥ 6.5.0, < 6.6.5+2 more2021-10-27
CVE-2021-34787 [MEDIUM] CWE-183 CVE-2021-34787: A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Secu A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices conf
nvd
CVE-2022-20940P4MEDIUMCVSS 5.3≥ 6.2.3, ≤ 6.2.3.18≥ 6.3.0, ≤ 6.3.0.5+15 more2022-11-15
CVE-2022-20940 [MEDIUM] CWE-203 CVE-2022-20940: A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an u A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption policies. An attacker could exploit t
nvd
CVE-2023-20246P4MEDIUMCVSS 5.3≥ 7.0.0, ≤ 7.3.1.12023-11-01
CVE-2023-20246 [MEDIUM] CWE-290 CVE-2023-20246: Multiple Cisco products are affected by a vulnerability in Snort access control policies that could Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs when the access control policies are being populated. An attacker could exploit this vulnerability
nvd
CVE-2026-20106P4MEDIUMCVSS 5.3≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20106 [MEDIUM] CWE-401 CVE-2026-20106: A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition requiring a manual reboot.
nvd
CVE-2023-20081P4MEDIUMCVSS 5.9v9.8.1v9.8.1.5+157 more2023-03-23
CVE-2023-20081 [MEDIUM] CWE-122 CVE-2023-20081: A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) S A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu
nvd
CVE-2023-20270P4MEDIUMCVSS 5.8v7.1.0v7.1.0.1+10 more2023-11-01
CVE-2023-20270 [MEDIUM] CWE-20 CVE-2023-20270: A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. This vulnerability is du
nvd
CVE-2021-34791P4MEDIUMCVSS 5.3fixed in 6.4.0.12≥ 6.5.0, < 6.6.5+1 more2021-10-27
CVE-2021-34791 [MEDIUM] CWE-358 CVE-2021-34791: Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For mo
nvd
CVE-2021-34790P4MEDIUMCVSS 5.3fixed in 6.4.0.12≥ 6.5.0, < 6.6.5+1 more2021-10-27
CVE-2021-34790 [MEDIUM] CWE-358 CVE-2021-34790: Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For mo
nvd
CVE-2021-34794P4MEDIUMCVSS 5.3≥ 6.4.0, < 6.4.0.13≥ 6.5.0, < 6.6.5+1 more2021-10-27
CVE-2021-34794 [MEDIUM] CWE-284 CVE-2021-34794: A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control function A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could
nvd
CVE-2023-20267P4MEDIUMCVSS 5.3≥ 6.7.0, ≤ 7.3.1.12023-11-01
CVE-2023-20267 [MEDIUM] CWE-284 CVE-2023-20267: A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attack A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restric
nvd
CVE-2026-20025P4MEDIUMCVSS 6.8≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20025 [MEDIUM] CWE-190 CVE-2026-20025: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key. This vulnerability is due to insufficient
nvd
CVE-2020-3582P4MEDIUMCVSS 6.1≥ 6.4.0, < 6.4.0.102020-10-21
CVE-2020-3582 [MEDIUM] CWE-79 CVE-2020-3582: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2020-3581P4MEDIUMCVSS 6.1≥ 6.4.0, < 6.4.0.102020-10-21
CVE-2020-3581 [MEDIUM] CWE-79 CVE-2020-3581: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd