VendorsCiscofirepower_4115any version
Vulnerabilities

Cisco Firepower 4115 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

40CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2022-20829
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
Published 2022-06-24 · Modified
9.1EPSS 0.034
CVE-2022-20828
Cisco FirePOWER Software for ASA FirePOWER Module Command Injection Vulnerability
Published 2022-06-24 · Modified
9.0EPSS 0.493
CVE-2020-3172
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Arbitrary Code Execution and Denial of Service Vulnerability
Published 2020-02-26 · Modified
8.8EPSS 0.019
CVE-2019-12675
Cisco Firepower Threat Defense Software Multi-instance Container Escape Vulnerabilities
Published 2019-10-02 · Modified
8.8EPSS 0.007
CVE-2020-3456
Cisco FXOS Software Firepower Chassis Manager Cross-Site Request Forgery Vulnerability
Published 2020-10-21 · Modified
8.8EPSS 0.006
CVE-2021-1368
Cisco FXOS and NX-OS Software Unidirectional Link Detection Denial of Service and Arbitrary Code Execution Vulnerability
Published 2021-02-24 · Modified
8.8EPSS 0.005
CVE-2020-3517
Cisco FXOS and NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
Published 2020-08-27 · Modified
8.6EPSS 0.014
CVE-2020-3571
Cisco Firepower 4110 ICMP Flood Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.014
CVE-2022-20751
Cisco Firepower Threat Defense Software Snort Out of Memory Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.013
CVE-2019-12674
Cisco Firepower Threat Defense Software Multi-instance Container Escape Vulnerabilities
Published 2019-10-02 · Modified
8.2EPSS 0.008
CVE-2020-3167
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
Published 2020-02-26 · Modified
7.8EPSS 0.009
CVE-2020-3171
Cisco FXOS and UCS Manager Software Local Management CLI Command Injection Vulnerability
Published 2020-02-26 · Modified
7.8EPSS 0.005
CVE-2020-3459
Cisco FXOS Software for Firepower 4100/9300 Series Command Injection Vulnerability
Published 2020-10-21 · Modified
7.8EPSS 0.004
CVE-2020-3455
Cisco FXOS Software for Firepower 4100/9300 Series Appliances Secure Boot Bypass Vulnerability
Published 2020-10-21 · Modified
7.8EPSS 0.003
CVE-2021-1448
Cisco Firepower Threat Defense Software Command Injection Vulnerability
Published 2021-04-29 · Modified
7.8EPSS 0.003
CVE-2023-20200
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the improper handling of specific SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: This vulnerability affects all supported SNMP versions. To exploit this vulnerability through SNMPv2c or earlier, an attacker must know the SNMP community string that is configured on an affected device. To exploit this vulnerability through SNMPv3, the attacker must have valid credentials for an SNMP user who is configured on the affected device.
Published 2023-08-23 · Modified
7.7EPSS 0.007
CVE-2022-20866
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability
Published 2022-08-10 · Modified
7.5EPSS 0.174
CVE-2019-12697
Cisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass Vulnerabilities
Published 2019-10-02 · Modified
7.5EPSS 0.015
CVE-2019-12696
Cisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass Vulnerabilities
Published 2019-10-02 · Modified
7.5EPSS 0.015
CVE-2022-20795
Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense Software AnyConnect SSL VPN Denial of Service Vulnerability
Published 2022-04-21 · Modified
7.5EPSS 0.007
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1779
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1780
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.005
CVE-2020-3169
Cisco FXOS Software CLI Command Injection Vulnerability
Published 2020-02-26 · Modified
7.2EPSS 0.004
CVE-2020-3457
Cisco FXOS Software Command Injection Vulnerability
Published 2020-10-21 · Modified
7.2EPSS 0.004
CVE-2020-3545
Cisco FXOS Software Buffer Overflow Vulnerability
Published 2020-09-04 · Modified
7.2EPSS 0.004
CVE-2019-1728
Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.002
CVE-2021-1489
Cisco Firepower Device Manager Software Filesystem Space Exhaustion Denial of Service Vulnerability
Published 2021-04-29 · Modified
6.8EPSS 0.012
CVE-2022-20865
Cisco FXOS Software Command Injection Vulnerability
Published 2022-08-25 · Modified
6.7EPSS 0.003
CVE-2020-3166
Cisco FXOS Software CLI Arbitrary File Read and Write Vulnerability
Published 2020-02-26 · Modified
6.7EPSS 0.003
CVE-2023-20015
Cisco Firepower 4100 Series, Firepower 9300 Security Appliances, and UCS Fabric Interconnects Command Injection Vulnerability
Published 2023-02-23 · Modified
6.7EPSS 0.002
CVE-2024-20294
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device and having an authenticated user retrieve LLDP statistics from the affected device through CLI show commands or Simple Network Management Protocol (SNMP) requests. A successful exploit could allow the attacker to cause the LLDP service to crash and stop running on the affected device. In certain situations, the LLDP crash may result in a reload of the affected device. Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interface of an affected device, either physically or logically (for example, through a Layer 2 Tunnel configured to transport the LLDP protocol).
Published 2024-02-28 · Analyzed
6.6EPSS 0.003
CVE-2019-1690
Cisco Application Policy Infrastructure Controller IPv6 Link-Local Address Vulnerability
Published 2019-03-11 · Modified
6.5EPSS 0.006
CVE-2023-20016
Cisco FXOS Software and UCS Manager Software Configuration Backup Static Key Vulnerability
Published 2023-02-23 · Modified
6.5EPSS 0.001
CVE-2022-20625
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Service Denial of Service Vulnerability
Published 2022-02-23 · Modified
6.1EPSS 0.033
CVE-2023-20234
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker could exploit this vulnerability by authenticating to an affected device and using the command at the CLI. A successful exploit could allow the attacker to overwrite any file on the disk of the affected device, including system files. The attacker must have valid administrative credentials on the affected device to exploit this vulnerability.
Published 2023-08-23 · Modified
6.0EPSS 0.002
CVE-2019-1734
Cisco FXOS and NX-OS Software Sensitive File Read Information Disclosure Vulnerability
Published 2019-11-05 · Modified
5.5EPSS 0.003
CVE-2020-3504
Cisco UCS Manager Software Local Management CLI Denial of Service Vulnerability
Published 2020-08-27 · Modified
3.3EPSS 0.003