cbcvebase.

Cisco Secure Firewall Threat Defense vulnerabilities

269 known vulnerabilities affecting cisco/secure_firewall_threat_defense.

Total CVEs
269
CISA KEV
13
actively exploited
Public exploits
9
Exploited in wild
18
Severity breakdown
CRITICAL6HIGH137MEDIUM125LOW1

Vulnerabilities

Page 7 of 14
CVE-2022-20746P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20746 [HIGH] CWE-476 CVE-2022-20746: A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software coul A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper handling of TCP flows. An attacker could exploit this vulnerability by sending a crafted stream of TCP traffic through an a
nvd
CVE-2022-20729P3HIGHCVSS 7.8fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20729 [HIGH] CWE-91 CVE-2022-20729: A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject XML into the command parser. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted input in commands. A successful exploit could allow the attacker to inje
nvd
CVE-2022-20795P3HIGHCVSS 7.5≤ 7.0.1≥ 7.1.0.0, ≤ 7.1.0.12022-04-21
CVE-2022-20795 [HIGH] CWE-345 CVE-2022-20795: A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processi
nvd
CVE-2019-12674P3HIGHCVSS 8.2fixed in 6.4.0.22019-10-02
CVE-2019-12674 [HIGH] CWE-216 CVE-2019-12674: Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Softw Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An a
nvd
CVE-2017-6632P3HIGHCVSS 7.5v5.3.0v5.4.0+8 more2017-05-22
CVE-2017-6632 [HIGH] CWE-399 CVE-2017-6632: A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePO A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging of certain TCP packets by the affecte
nvd
CVE-2019-1704P3HIGHCVSS 7.5≥ 6.0.0, < 6.2.3.122019-05-03
CVE-2019-1704 [HIGH] CWE-400 CVE-2019-1704: Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine fo Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3179P3HIGHCVSS 7.5≥ 6.3.0, < 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3179 [HIGH] CWE-415 CVE-2020-3179: A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Fir A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory handling error when GRE over IPv6 traffic is processed. An attack
nvd
CVE-2021-1422P3HIGHCVSS 7.7v7.0.0.02021-07-16
CVE-2021-1422 [HIGH] CWE-617 CVE-2021-1422: A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Softw A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle position to cause an unexpected reload of the device that results in a denial of service (DoS) condit
nvd
CVE-2021-34792P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.0.13≥ 6.6.0, < 6.6.5+2 more2021-10-27
CVE-2021-34792 [HIGH] CWE-400 CVE-2021-34792: A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Fir A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacke
nvd
CVE-2021-34781P3HIGHCVSS 7.5≥ 6.3.0, < 6.4.0.13≥ 6.5.0, < 6.6.5+2 more2021-10-27
CVE-2021-34781 [HIGH] CWE-119 CVE-2021-34781: A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepow A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an SSH session fails to be establishe
nvd
CVE-2021-1501P3HIGHCVSS 7.5≥ 6.2.2, < 6.4.0.12≥ 6.5.0, < 6.6.4+1 more2021-04-29
CVE-2021-1501 [HIGH] CWE-613 CVE-2021-1501: A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition.The vulnerability is due to a crash that occurs during a has
nvd
CVE-2022-20751P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20751 [HIGH] CWE-770 CVE-2022-20751: A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) S A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient memory management for certain Snort e
nvd
CVE-2020-3306P3HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.42020-05-06
CVE-2020-3306 [HIGH] CWE-400 CVE-2020-3306: A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incorrect processing of certain DHCP packets. An attacker could exploit t
nvd
CVE-2020-3305P3HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3305 [HIGH] CWE-400 CVE-2020-3305: A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP packets. An at
nvd
CVE-2022-20757P3HIGHCVSS 7.5fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20757 [HIGH] CWE-770 CVE-2022-20757: A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper traffic handling when platform limits are reached. An attacker could exploit this vulnerability by
nvd
CVE-2020-3317P3HIGHCVSS 7.5fixed in 6.4.0.10≥ 6.5.0, < 6.5.0.52020-10-21
CVE-2020-3317 [HIGH] CWE-20 CVE-2020-3317: A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software cou A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component. An attacker could exploit this vulnerability by sending a malformed TLS packet through a Cisco
nvd
CVE-2022-20946P3HIGHCVSS 7.5≥ 6.3.0, ≤ 6.3.0.5≥ 6.4.0, ≤ 6.4.0.15+7 more2022-11-15
CVE-2022-20946 [HIGH] CWE-122 CVE-2022-20946: A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Fir A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory handling error that occurs when GRE traffic is processed. An a
nvd
CVE-2022-20854P3HIGHCVSS 7.5≥ 6.1.0, ≤ 6.1.0.7≥ 6.2.0, ≤ 6.2.0.6+23 more2022-11-15
CVE-2022-20854 [HIGH] CWE-400 CVE-2022-20854: A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when an SSH session fails to be establi
nvd
CVE-2018-0453P3HIGHCVSS 8.2v5.4.0v6.0.0+5 more2018-10-05
CVE-2018-0453 [HIGH] CWE-264 CVE-2018-0453: A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with root privileges on the Cisco Firepower Management Center (FMC), or through Cisco FMC on other Firepower sensors and
nvd
CVE-2020-3303P3HIGHCVSS 7.5fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.62020-05-06
CVE-2020-3303 [HIGH] CWE-399 CVE-2020-3303: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could expl
nvd
Cisco Secure Firewall Threat Defense vulnerabilities | cvebase