cbcvebase.

Cisco Secure Firewall Threat Defense vulnerabilities

269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.

Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1

Vulnerabilities

Page 3 of 14
CVE-2018-0230P3HIGHCVSS 8.6v6.2.1v6.2.22018-04-19
CVE-2018-0230 [HIGH] CWE-400 CVE-2018-0230: A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (F A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to the affe
nvd
CVE-2019-15256P3HIGHCVSS 8.6≥ 6.2.0, < 6.2.3.11≥ 6.3.0, < 6.3.0.22019-10-02
CVE-2019-15256 [HIGH] CWE-399 CVE-2019-15256: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper ma
nvd
CVE-2020-3191P3HIGHCVSS 8.6≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+1 more2020-05-06
CVE-2020-3191 [HIGH] CWE-20 CVE-2020-3191: A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Softw A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper length validation of a field
nvd
CVE-2019-12675P3HIGHCVSS 8.8fixed in 6.4.0.22019-10-02
CVE-2019-12675 [HIGH] CWE-216 CVE-2019-12675: Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Softw Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An a
nvd
CVE-2023-20086P3HIGHCVSS 8.6v6.2.3v6.2.3.1+69 more2023-11-01
CVE-2023-20086 [HIGH] CWE-248 CVE-2023-20086: A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco F A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of ICMPv6 messages. An attacker could exploit this vulnerability by sen
nvd
CVE-2023-20095P3HIGHCVSS 8.6v6.2.3v6.2.3.0+56 more2023-11-01
CVE-2023-20095 [HIGH] CWE-772 CVE-2023-20095: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of HTTPS requests. An attacker could ex
nvd
CVE-2024-20495P3HIGHCVSS 8.6v6.2.3.16v6.2.3.17+43 more2024-10-23
CVE-2024-20495 [HIGH] CWE-20 CVE-2024-20495: A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper v
nvd
CVE-2020-3196P3HIGHCVSS 8.6≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-05-06
CVE-2020-3196 [HIGH] CWE-400 CVE-2020-3196: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Ad A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of service (DoS) condition. The vulnerabilit
nvd
CVE-2018-15388P3HIGHCVSS 8.6fixed in 6.2.3.122019-05-03
CVE-2018-15388 [HIGH] CWE-400 CVE-2018-15388: A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for existing WebVPN login operations. An attacke
nvd
CVE-2020-3283P3HIGHCVSS 8.6≥ 6.4.0, < 6.4.0.92020-05-06
CVE-2020-3283 [HIGH] CWE-119 CVE-2020-3283: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Fi A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communicatio
nvd
CVE-2020-3373P3HIGHCVSS 8.6v6.6.0.12020-10-21
CVE-2020-3373 [HIGH] CWE-400 CVE-2020-3373: A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. This memory leak could prevent traffic from being processed through the device, resulting in a denia
nvd
CVE-2020-3562P3HIGHCVSS 8.6v6.3.0v6.4.0+1 more2020-10-21
CVE-2020-3562 [HIGH] CWE-119 CVE-2020-3562: A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation for certain fields of specific SSL/TLS messages. An
nvd
CVE-2023-20083P3HIGHCVSS 8.6≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.17+6 more2023-11-01
CVE-2023-20083 [HIGH] CWE-835 CVE-2023-20083: A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Fir A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of service (DoS) condition. FTD managemen
nvd
CVE-2021-34793P3HIGHCVSS 8.6fixed in 6.4.0.13≥ 6.5.0, < 6.6.5+1 more2021-10-27
CVE-2021-34793 [HIGH] CWE-924 CVE-2021-34793: A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepo A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is due to incorrect handling of certai
nvd
CVE-2020-3549P3HIGHCVSS 8.1fixed in 6.6.12020-10-21
CVE-2020-3549 [HIGH] CWE-326 CVE-2020-3549: A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software an A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due to insufficient sftunnel negotiation protection during initial device registration. An attacke
nvd
CVE-2021-1223P3HIGHCVSS 7.5fixed in 6.7.02021-01-13
CVE-2021-1223 [HIGH] CWE-693 CVE-2021-1223: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected de
nvd
CVE-2019-1708P3HIGHCVSS 8.6≥ 6.2.2, ≤ 6.2.3.12≥ 6.3.0, ≤ 6.3.0.32019-05-03
CVE-2019-1708 [HIGH] CWE-404 CVE-2019-1708: A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) fe A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (Do
nvd
CVE-2020-3572P3HIGHCVSS 8.6fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+1 more2020-10-21
CVE-2020-3572 [HIGH] CWE-400 CVE-2020-3572: A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software a A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak when closing SSL/TLS connections in a specific s
nvd
CVE-2021-1402P3HIGHCVSS 8.6≥ 6.3.0, < 6.4.0≥ 6.5.0, < 6.6.02021-04-29
CVE-2021-1402 [HIGH] CWE-119 CVE-2021-1402: A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs softwa
nvd
CVE-2019-1669P3HIGHCVSS 8.6v6.3.0v6.4.02019-01-24
CVE-2019-1669 [HIGH] CWE-693 CVE-2019-1669: A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Soft A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition. The vulnerability exists because the affected software improperly manages system memory resources when inspecti
nvd