VendorsCiscofirepower_1010any version
Vulnerabilities

Cisco Firepower 1010 - any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2024-20412
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device.
Published 2024-10-23 · Analyzed
9.3EPSS 0.002
CVE-2022-20829
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
Published 2022-06-24 · Modified
9.1EPSS 0.034
CVE-2022-20828
Cisco FirePOWER Software for ASA FirePOWER Module Command Injection Vulnerability
Published 2022-06-24 · Modified
9.0EPSS 0.493
CVE-2020-3283
Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability
Published 2020-05-06 · Modified
8.6EPSS 0.020
CVE-2021-1402
Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
Published 2021-04-29 · Modified
8.6EPSS 0.014
CVE-2022-20751
Cisco Firepower Threat Defense Software Snort Out of Memory Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.013
CVE-2020-3167
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
Published 2020-02-26 · Modified
7.8EPSS 0.009
CVE-2022-20866
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability
Published 2022-08-10 · Modified
7.5EPSS 0.174
CVE-2019-12697
Cisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass Vulnerabilities
Published 2019-10-02 · Modified
7.5EPSS 0.015
CVE-2019-12696
Cisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass Vulnerabilities
Published 2019-10-02 · Modified
7.5EPSS 0.015
CVE-2022-20795
Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense Software AnyConnect SSL VPN Denial of Service Vulnerability
Published 2022-04-21 · Modified
7.5EPSS 0.007
CVE-2020-3457
Cisco FXOS Software Command Injection Vulnerability
Published 2020-10-21 · Modified
7.2EPSS 0.004
CVE-2021-1488
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000 and 2100 Series Appliances Command Injection Vulnerability
Published 2021-04-29 · Modified
7.2EPSS 0.003
CVE-2021-1489
Cisco Firepower Device Manager Software Filesystem Space Exhaustion Denial of Service Vulnerability
Published 2021-04-29 · Modified
6.8EPSS 0.012
CVE-2020-3458
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000/2100 Series Appliances Secure Boot Bypass Vulnerabilities
Published 2020-10-21 · Modified
6.7EPSS 0.003
CVE-2020-3166
Cisco FXOS Software CLI Arbitrary File Read and Write Vulnerability
Published 2020-02-26 · Modified
6.7EPSS 0.003
CVE-2023-20234
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker could exploit this vulnerability by authenticating to an affected device and using the command at the CLI. A successful exploit could allow the attacker to overwrite any file on the disk of the affected device, including system files. The attacker must have valid administrative credentials on the affected device to exploit this vulnerability.
Published 2023-08-23 · Modified
6.0EPSS 0.002
CVE-2020-3585
Cisco Firepower 1000 Series Bleichenbacher Attack Vulnerability
Published 2020-10-21 · Modified
5.3EPSS 0.013
CVE-2020-3504
Cisco UCS Manager Software Local Management CLI Denial of Service Vulnerability
Published 2020-08-27 · Modified
3.3EPSS 0.003