cbcvebase.

Cisco Secure Firewall Threat Defense vulnerabilities

269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.

Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1

Vulnerabilities

Page 14 of 14
CVE-2018-15398P4MEDIUMCVSS 4.0v6.2.02018-10-05
CVE-2018-15398 [MEDIUM] CWE-284 CVE-2018-15398: A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an affected device. The vulnerability is due to errors that could occur wh
nvd
CVE-2023-20275P4MEDIUMCVSS 4.3v6.2.3v6.2.3.1+71 more2023-12-12
CVE-2023-20275 [MEDIUM] CWE-346 CVE-2023-20275: A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Softwar A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the packet's inner source IP address after
nvd
CVE-2026-20069P4MEDIUMCVSS 4.3≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20069 [MEDIUM] CWE-444 CVE-2026-20069: A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of HTTP r
nvd
CVE-2019-1701P4MEDIUMCVSS 4.8≥ 6.2.1, < 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1701 [MEDIUM] CWE-79 CVE-2019-1701: Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software a Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal of an affected device. The vulnerabilities exist because the software insuff
nvd
CVE-2026-20021P4MEDIUMCVSS 4.3v6.4.0v6.4.0.1+74 more2026-03-04
CVE-2026-20021 [MEDIUM] CWE-401 CVE-2026-20021: A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improperly validating
nvd
CVE-2021-34763P4MEDIUMCVSS 4.8fixed in 6.4.0.13≥ 6.5.0, < 6.6.5+1 more2021-10-27
CVE-2021-34763 [MEDIUM] CWE-601 CVE-2021-34763: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2023-20177P4MEDIUMCVSS 4.0v7.0.0v7.0.0.1+19 more2023-11-01
CVE-2023-20177 [MEDIUM] CWE-244 CVE-2023-20177: A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Softwa A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability exists beca
nvd
CVE-2023-20070P4MEDIUMCVSS 4.0v7.2.0v7.2.0.12023-11-01
CVE-2023-20070 [MEDIUM] CWE-244 CVE-2023-20070: A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software c A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability is due to a logic error in how memory allocations are handled during a TLS 1.3 session. Under specific, time-based constra
nvd
CVE-2020-3585P4LOWCVSS 3.7fixed in 6.4.0.102020-10-21
CVE-2020-3585 [LOW] CWE-203 CVE-2020-3585: A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper implementation of countermeasures against the Bleic
nvd