Cisco Secure Firewall Threat Defense vulnerabilities
269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.
Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1
Vulnerabilities
Page 13 of 14
CVE-2026-20023P4MEDIUMCVSS 6.5v6.4.0v6.4.0.1+73 more2026-03-04
CVE-2026-20023 [MEDIUM] CWE-787 CVE-2026-20023: A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to corrupt memory on an affected device, resulting in a denial of service (DoS) condition.
This vulnerability is due to memory corruption wh
nvd
CVE-2020-3583P4MEDIUMCVSS 6.1≥ 6.4.0, < 6.4.0.102020-10-21
CVE-2020-3583 [MEDIUM] CWE-79 CVE-2020-3583: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insu
nvd
CVE-2017-3887P4MEDIUMCVSS 5.9v6.0.1v6.1.0+1 more2017-04-07
CVE-2017-3887 [MEDIUM] CWE-755 CVE-2017-3887: A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Fi
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts. This vulnerability affects Cisco Firepower System Software prior to the first fixed rel
nvd
CVE-2020-3188P4MEDIUMCVSS 5.3≥ 6.4.0, < 6.4.0.9≥ 6.5.0, < 6.5.0.52020-05-06
CVE-2020-3188 [MEDIUM] CWE-399 CVE-2020-3188: A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for ma
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition. The vulnerability exists because the default sessi
nvd
CVE-2026-20020P4MEDIUMCVSS 5.7v6.4.0v6.4.0.1+72 more2026-03-04
CVE-2026-20020 [MEDIUM] CWE-20 CVE-2026-20020: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. If OSPF authentication is enabled, the attacker must know the secret key to exploit this vulnerability.
This vulner
nvd
CVE-2024-20493P4MEDIUMCVSS 5.3v6.2.3v6.2.3.1+89 more2024-10-23
CVE-2024-20493 [MEDIUM] CWE-772 CVE-2024-20493: A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Ci
A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in a temporary denial of service (
nvd
CVE-2024-20355P4MEDIUMCVSS 5.0v6.2.3v6.2.3.1+72 more2024-05-22
CVE-2024-20355 [MEDIUM] CWE-862 CVE-2024-20355: A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN service
A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to successfully establish a VPN session on an affected device. This vulnerability is due to improper
nvd
CVE-2022-20950P4MEDIUMCVSS 5.3v7.2.0v7.2.0.12022-11-15
CVE-2022-20950 [MEDIUM] CWE-770 CVE-2022-20950: A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD) Softw
A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart.
This vulnerability is due to a lack of error-checking when SIP bidirectional flows are being inspected by Snort 3. An attacker could exploit this vul
nvd
CVE-2023-20031P4MEDIUMCVSS 5.4v6.7.0v6.7.0.1+13 more2023-11-01
CVE-2023-20031 [MEDIUM] CWE-244 CVE-2023-20031: A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cis
A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a logic error that occurs when an SSL/TLS certificate that is under load is acces
nvd
CVE-2022-20949P4MEDIUMCVSS 4.9≥ 6.1.0, ≤ 6.1.0.7≥ 6.2.0, ≤ 6.2.0.6+14 more2022-11-15
CVE-2022-20949 [MEDIUM] CWE-399 CVE-2022-20949: A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could
A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with high privileges to execute configuration commands on an affected system.
This vulnerability exists because access to HTTPS endpoints is not properly restricted on an affected device. An attacker could exploi
nvd
CVE-2026-20064P4MEDIUMCVSS 6.5v6.2.3v6.4.0+74 more2026-03-04
CVE-2026-20064 [MEDIUM] CWE-476 CVE-2026-20064: A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticat
A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition.
This vulnerability is due to improper validation of user-supplied input. An attacker with a low-privileged account could exploit this vulnerabi
nvd
CVE-2019-12695P4MEDIUMCVSS 6.1fixed in 6.2.3.15≥ 6.3.0, < 6.3.0.5+1 more2019-10-02
CVE-2019-12695 [MEDIUM] CWE-79 CVE-2019-12695: A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA)
A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to in
nvd
CVE-2026-20024P4MEDIUMCVSS 5.7v6.4.0v6.4.0.1+66 more2026-03-04
CVE-2026-20024 [MEDIUM] CWE-119 CVE-2026-20024: A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key.
This vulnerability is due to heap corrupt
nvd
CVE-2020-3352P4MEDIUMCVSS 5.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3352 [MEDIUM] CWE-912 CVE-2020-3352: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacker could exploit this vulnerability by performing specific steps that make the hidden commands accessible. A succes
nvd
CVE-2017-3806P4MEDIUMCVSS 5.3v5.3.0v5.4.0+3 more2017-02-03
CVE-2017-3806 [MEDIUM] CWE-78 CVE-2017-3806: A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewal
A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the device. More Information: CSCvb61343. Known Affected Releases: 2.0(1.68). Known Fixed Releases: 2.0(1.1
nvd
CVE-2020-3308P4MEDIUMCVSS 4.9fixed in 6.2.2.12020-05-06
CVE-2020-3308 [MEDIUM] CWE-347 CVE-2020-3308: A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD)
A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker
nvd
CVE-2021-34764P4MEDIUMCVSS 6.1fixed in 6.4.0.13≥ 6.5.0, < 6.6.5+1 more2021-10-27
CVE-2021-34764 [MEDIUM] CWE-601 CVE-2021-34764: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20748P4MEDIUMCVSS 5.3v7.0.02022-05-03
CVE-2022-20748 [MEDIUM] CWE-664 CVE-2022-20748: A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Softwa
A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficient error handling in the local malware analysis process of an affected device. An attacker c
nvd
CVE-2020-3561P4MEDIUMCVSS 4.7fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3561 [MEDIUM] CWE-93 CVE-2020-3561: A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Softwa
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the affected system. The vulnerability is due to improper input sanitization. An attacker could expl
nvd
CVE-2023-20247P4MEDIUMCVSS 4.3v6.2.3v6.2.3.1+65 more2023-11-01
CVE-2023-20247 [MEDIUM] CWE-288 CVE-2023-20247: A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Soft
A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and password. This vulnerability is due to i
nvd