cbcvebase.

Cisco Secure Firewall Threat Defense vulnerabilities

269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.

Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1

Vulnerabilities

Page 2 of 14
CVE-2021-34762P3HIGHCVSS 8.1fixed in 6.4.0.13≥ 6.5.0, < 6.6.5+2 more2021-10-27
CVE-2021-34762 [HIGH] CWE-26 CVE-2021-34762: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input validation of the HTTPS URL by the web-
nvd
CVE-2020-3550P3HIGHCVSS 8.1≤ 6.0.1≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3550 [HIGH] CWE-22 CVE-2020-3550: A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Fi A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to perform directory traversal and access directories outside the restricted path. The vulnerability is due to insufficient input validation. An attacker could exploit this
nvd
CVE-2024-20342P3HIGHCVSS 8.6fixed in 7.0.6.2≥ 7.2.0, < 7.2.6+3 more2024-10-23
CVE-2024-20342 [HIGH] CWE-1025 CVE-2024-20342: Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort d Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic th
nvd
CVE-2019-1714P3HIGHCVSS 8.6≥ 6.2.1, < 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1714 [HIGH] CWE-255 CVE-2019-1714: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-O A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN
nvd
CVE-2026-20103P3HIGHCVSS 8.6≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20103 [HIGH] CWE-770 CVE-2026-20103: A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access SSL VPN connections. This does no
nvd
CVE-2018-0231P3HIGHCVSS 8.6≥ 6.0, < 6.1.0.6≥ 6.2.1, < 6.2.2.12018-04-19
CVE-2018-0231 [HIGH] CWE-20 CVE-2018-0231: A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance ( A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validatio
nvd
CVE-2020-3304P3HIGHCVSS 8.6fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3304 [HIGH] CWE-400 CVE-2020-3304: A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepow A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP re
nvd
CVE-2026-20039P3HIGHCVSS 8.6≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.10+3 more2026-03-04
CVE-2026-20039 [HIGH] CWE-244 CVE-2026-20039: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Sof A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to ineffective memory management of the VPN web
nvd
CVE-2026-20101P3HIGHCVSS 8.6≥ 6.4.0, < 7.0.9≥ 7.1.0, < 7.2.11+3 more2026-03-04
CVE-2026-20101 [HIGH] CWE-330 CVE-2026-20101: A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software a A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could ex
nvd
CVE-2025-20182P3HIGHCVSS 8.6v6.2.3v6.2.3.1+84 more2025-05-07
CVE-2025-20182 [HIGH] CWE-787 CVE-2025-20182: A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vu
nvd
CVE-2018-0240P3HIGHCVSS 8.6≥ 6.1.0, ≤ 6.1.0.7≥ 6.2.0, < 6.2.0.5+1 more2018-04-19
CVE-2018-0240 [HIGH] CWE-399 CVE-2018-0240: Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Secu Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to log
nvd
CVE-2018-0228P3HIGHCVSS 8.6≥ 6.0, < 6.1.0.6≥ 6.2.0, < 6.2.0.5+1 more2018-04-19
CVE-2018-0228 [HIGH] CWE-20 CVE-2018-0228: A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incorrect handling of an internal software lock that
nvd
CVE-2019-1703P3HIGHCVSS 8.6≥ 6.2.1, < 6.2.3.122019-05-03
CVE-2019-1703 [HIGH] CWE-400 CVE-2019-1703: A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (F A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error, which may
nvd
CVE-2020-3436P3HIGHCVSS 8.6≤ 6.2.2≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3436 [HIGH] CWE-434 CVE-2020-3436: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco F A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload. The vulnerability exists because the affecte
nvd
CVE-2022-20715P3HIGHCVSS 8.6fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20715 [HIGH] CWE-399 CVE-2022-20715: A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Sof A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation of errors that are logged as a r
nvd
CVE-2023-20244P3HIGHCVSS 8.6v6.2.3v6.2.3.1+68 more2023-11-01
CVE-2023-20244 [HIGH] CWE-771 CVE-2023-20244: A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) Software f A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain packets when they are sent to the insp
nvd
CVE-2024-20402P3HIGHCVSS 8.6v6.2.3v6.2.3.1+85 more2024-10-23
CVE-2024-20402 [HIGH] CWE-788 CVE-2024-20402: A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisc A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a logic error in memory manageme
nvd
CVE-2024-20426P3HIGHCVSS 8.6v7.2.0v7.2.0.1+19 more2024-10-23
CVE-2024-20426 [HIGH] CWE-476 CVE-2024-20426: A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient i
nvd
CVE-2024-20494P3HIGHCVSS 8.6v7.3.0v7.3.1+6 more2024-10-23
CVE-2024-20494 [HIGH] CWE-1287 CVE-2024-20494: A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Sof A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper data validation
nvd
CVE-2019-1694P3HIGHCVSS 8.6fixed in 6.2.3.12≥ 6.3.0, < 6.3.0.32019-05-03
CVE-2019-1694 [HIGH] CWE-20 CVE-2019-1694: A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper handling of TCP traffic. An att
nvd
Cisco Secure Firewall Threat Defense vulnerabilities | cvebase