Cisco Secure Firewall Threat Defense vulnerabilities
269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.
Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1
Vulnerabilities
Page 6 of 14
CVE-2022-20767P3HIGHCVSS 7.5fixed in 7.0.2v7.1.02022-05-03
CVE-2022-20767 [HIGH] CWE-399 CVE-2022-20767: A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Softwa
A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of the DNS reputation enforcement rule. An attacker could exploit this vulnerability by
nvd
CVE-2021-34783P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34783 [HIGH] CWE-119 CVE-2021-34783: A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (
A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient validation of SS
nvd
CVE-2022-20745P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20745 [HIGH] CWE-20 CVE-2022-20745: A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Secur
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS request
nvd
CVE-2025-20127P3HIGHCVSS 7.7v7.4.0v7.4.1+4 more2025-08-14
CVE-2025-20127 [HIGH] CWE-404 CVE-2025-20127: A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adapti
A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are associated with incoming TLS 1.3 co
nvd
CVE-2021-34755P3HIGHCVSS 7.8≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34755 [HIGH] CWE-20 CVE-2021-34755: Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-34756P3HIGHCVSS 7.8≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34756 [HIGH] CWE-20 CVE-2021-34756: Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2024-20408P3HIGHCVSS 7.7v6.2.3v6.2.3.1+88 more2024-10-23
CVE-2024-20408 [HIGH] CWE-1287 CVE-2024-20408: A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (A
A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need valid remote access VPN user credenti
nvd
CVE-2022-20947P3HIGHCVSS 7.5v6.1.0v6.1.0.1+84 more2022-11-15
CVE-2022-20947 [HIGH] CWE-119 CVE-2022-20947: A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance
A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper processing of HostSc
nvd
CVE-2023-20006P3HIGHCVSS 7.5v7.2.1v7.2.2+1 more2023-06-28
CVE-2023-20006 [HIGH] CWE-681 CVE-2023-20006: A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security
A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do
nvd
CVE-2024-20339P3HIGHCVSS 7.5v6.2.3v6.2.3.1+78 more2024-10-23
CVE-2024-20339 [HIGH] CWE-476 CVE-2024-20339: A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for C
A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to an issue that occurs when TLS traffic is processed. An attacker could exploit th
nvd
CVE-2024-20330P3HIGHCVSS 7.5v7.0.0.0v7.0.0.1+35 more2024-10-23
CVE-2024-20330 [HIGH] CWE-788 CVE-2024-20330: A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat De
A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause memory corruption, which could cause the Snort detection engine to restart unexpectedly.
This vulnerability is due to improper memo
nvd
CVE-2018-15383P3HIGHCVSS 7.5v6.0.1v6.1.0+3 more2018-10-05
CVE-2018-15383 [HIGH] CWE-400 CVE-2018-15383: A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Applianc
A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the af
nvd
CVE-2019-12698P3HIGHCVSS 7.5fixed in 6.2.3.15≥ 6.3.0, < 6.3.0.5+1 more2019-10-02
CVE-2019-12698 [HIGH] CWE-400 CVE-2019-12698: A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco
A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for a specific WebVPN HTTP page request. An attacker c
nvd
CVE-2020-3195P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.9≥ 6.5.0, < 6.5.0.52020-05-06
CVE-2020-3195 [HIGH] CWE-400 CVE-2020-3195: A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security App
A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to incorrect processing of certain OSPF packets. An attacker cou
nvd
CVE-2019-12678P3HIGHCVSS 7.5fixed in 6.2.3.15≥ 6.3.0, < 6.3.0.4+1 more2019-10-02
CVE-2019-12678 [HIGH] CWE-191 CVE-2019-12678: A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Securit
A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper parsing of SIP messages
nvd
CVE-2020-3255P3HIGHCVSS 7.5≥ 6.2.3, < 6.2.3.16≥ 6.3.0, < 6.3.0.6+1 more2020-05-06
CVE-2020-3255 [HIGH] CWE-400 CVE-2020-3255: A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Softw
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a high rate of IPv4
nvd
CVE-2020-3555P3HIGHCVSS 7.5≤ 6.2.2≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3555 [HIGH] CWE-404 CVE-2020-3555: A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software an
A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a watchdog timeout and crash d
nvd
CVE-2021-40117P3HIGHCVSS 7.5fixed in 6.2.3.17≥ 6.3.0, < 6.4.0.13+3 more2021-10-27
CVE-2021-40117 [HIGH] CWE-119 CVE-2021-40117: A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and
A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incoming SSL/TLS packets are not properly processed. An at
nvd
CVE-2020-3528P3HIGHCVSS 7.5fixed in 6.3.0.6≥ 6.4.0, < 6.4.0.10+2 more2020-10-21
CVE-2020-3528 [HIGH] CWE-400 CVE-2020-3528: A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (
A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validatio
nvd
CVE-2021-40116P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5.1+2 more2021-10-27
CVE-2021-40116 [HIGH] CWE-241 CVE-2021-40116: Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthent
Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints.
nvd