VendorsCiscoasa_5585-xany version
Vulnerabilities

Cisco ASA 5585-X Series IPS SSP any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2020-3125
Cisco Adaptive Security Appliance Software Kerberos Authentication Bypass Vulnerability
Published 2020-05-06 · Modified
9.8EPSS 0.024
CVE-2019-1713
Cisco Adaptive Security Appliance Software Cross-Site Request Forgery Vulnerability
Published 2019-05-03 · Modified
9.3EPSS 0.011
CVE-2020-3187
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
Published 2020-05-06 · Modified
9.11 PoCEPSS 0.966
CVE-2022-20829
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
Published 2022-06-24 · Modified
9.1EPSS 0.034
CVE-2016-6366
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.
Published 2016-08-18 · Analyzed
8.8KEV1 PoCEPSS 0.876
CVE-2019-1694
Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software TCP Timer Handling Denial of Service Vulnerability
Published 2019-05-03 · Modified
8.6EPSS 0.025
CVE-2020-3283
Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability
Published 2020-05-06 · Modified
8.6EPSS 0.020
CVE-2020-3179
Cisco Firepower Threat Defense Software Generic Routing Encapsulation Tunnel IPv6 Denial of Service Vulnerability
Published 2020-05-06 · Modified
8.6EPSS 0.020
CVE-2018-15388
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Denial of Service Vulnerability
Published 2019-05-03 · Modified
8.6EPSS 0.020
CVE-2020-3254
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service Vulnerabilities
Published 2020-05-06 · Modified
8.6EPSS 0.020
CVE-2020-3195
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPF Packets Processing Memory Leak Vulnerability
Published 2020-05-06 · Modified
8.6EPSS 0.019
CVE-2020-3196
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Denial of Service Vulnerability
Published 2020-05-06 · Modified
8.6EPSS 0.019
CVE-2020-3191
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability
Published 2020-05-06 · Modified
8.6EPSS 0.019
CVE-2020-3189
Cisco Firepower Threat Defense Software VPN System Logging Denial of Service Vulnerability
Published 2020-05-06 · Modified
8.6EPSS 0.018
CVE-2019-12678
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SIP Inspection Denial of Service Vulnerability
Published 2019-10-02 · Modified
8.6EPSS 0.018
CVE-2019-12673
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software FTP Inspection Denial of Service Vulnerability
Published 2019-10-02 · Modified
8.6EPSS 0.018
CVE-2021-34783
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Software-Based SSL/TLS Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.016
CVE-2021-40117
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.015
CVE-2021-34792
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Resource Exhaustion Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2021-40118
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Denial of Service Vulnerabilities
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2021-34793
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.006
CVE-2016-6367
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
Published 2016-08-18 · Analyzed
7.8KEV1 PoCEPSS 0.226
CVE-2019-1687
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software TCP Proxy Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.029
CVE-2019-1697
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Lightweight Directory Access Protocol Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.020
CVE-2019-12698
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN CPU Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.8EPSS 0.020
CVE-2013-1218
Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7)sp1E4 allows remote attackers to cause a denial of service (Analysis Engine process hang or device reload) via fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCue51272.
Published 2013-07-18 · Modified
7.8EPSS 0.019
CVE-2013-1243
The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensors before 7.1(6)E4, and IPS 4300 sensors before 7.1(5)E4 allows remote attackers to cause a denial of service (MainApp process hang) via malformed IPv4 packets, aka Bug ID CSCtx18596.
Published 2013-07-18 · Modified
7.8EPSS 0.013
CVE-2020-3303
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IKEv1 Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2020-3305
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software BGP Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2020-3306
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DHCP Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2019-1693
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.7EPSS 0.020
CVE-2019-12677
Cisco Adaptive Security Appliance Software SSL VPN Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.7EPSS 0.015
CVE-2020-3452
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
Published 2020-07-22 · Analyzed
7.5KEV3 PoCEPSS 1.000
CVE-2020-3255
Cisco Firepower Threat Defense Software Packet Flood Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.5EPSS 0.018
CVE-2011-2054
Cisco ASA Secondary Authentication Bypass Vulnerability
Published 2020-02-19 · Modified
7.5EPSS 0.009
CVE-2022-20795
Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense Software AnyConnect SSL VPN Denial of Service Vulnerability
Published 2022-04-21 · Modified
7.5EPSS 0.007
CVE-2019-12676
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPF LSA Processing Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.4EPSS 0.005
CVE-2019-12693
Cisco Adaptive Security Appliance Software Secure Copy Denial of Service Vulnerability
Published 2019-10-02 · Modified
6.8EPSS 0.015
CVE-2021-40125
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IKEv2 Site-to-Site VPN Denial of Service Vulnerability
Published 2021-10-27 · Modified
6.5EPSS 0.010
CVE-2018-0242
A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvg33985.
Published 2018-04-19 · Modified
6.1EPSS 0.018
1 / 2Next →