Showing 15 vulnerabilities on this page for Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Signals CISA KEV Ransomware Nuclei
Cisco vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Cisco ASA and FTD Denial-of-Service Vulnerability

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust r

CWE-772Oct 23, 2024
CVSS5.8v3.1EPSS15.9%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco ASA and FTD Privilege Escalation Vulnerability

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a file when it is read from system flash m

CWE-94Apr 24, 2024
CVSS6.0v3.1EPSS19.4%PoCs1SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Cisco ASA and FTD Denial of Service Vulnerability

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a devic

CWE-835Apr 24, 2024
CVSS8.6v3.1EPSS70.7%PoCs1SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. This vulnerability is due to improper separation of authentication, authorization, and accoun

CWE-288CWE-863Sep 6, 2023
CVSS5.0v3.1EPSS21.6%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by

CWE-79Oct 21, 20201 related artifact
CVSS6.1v3.1EPSS85.6%PoCs4SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL VPN Direct Memory Access Denial of Service Vulnerability

A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to inefficient direct memory access (DMA) memory management during the negotiation phase of an SSL VPN connection. An attacker could exploit this vulnerability by sending a steady st

CWE-400Oct 21, 2020
CVSS8.6v3.1EPSS1.86%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing director

CWE-20CWE-22Jul 22, 20201 related artifact
CVSS7.5v3.1EPSS>99.9%PoCs28SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by

CWE-200May 6, 2020
CVSS7.5v3.1EPSS69.3%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software Denial of Service Vulnerability

A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of SIP traffic. An attacker could exploit this vulnerability by sending SIP requests designed to specifically trigger th

CWE-20Nov 1, 2018
CVSS8.6v3.0EPSS4.38%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the

CWE-20CWE-22Jun 7, 20181 related artifact
CVSS7.5v3.1EPSS99.9%PoCs8SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Double Free

A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the

CWE-415Jan 29, 2018
CVSS10.0v3.0EPSS86.8%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

CWE-77Aug 18, 2016
CVSS7.8v3.1EPSS22.6%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

CWE-119CWE-120Aug 18, 2016
CVSS8.8v3.1EPSS87.6%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Improper Authentication

The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement authentication, which allows remote attackers to modify RAMFS customization objects via unspecified vectors, as demonstrated by inserting XSS sequences or capturing credentials, aka Bug ID CSCup36829.

CWE-20CWE-287Oct 10, 2014
CVSS4.3v2.0EPSS1.99%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.

CWE-79Mar 19, 2014
CVSS6.1v3.1EPSS18.9%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX