VendorsCiscofirepower_services_software_for_asaany version
Vulnerabilities

Cisco FirePOWER Services Software for ASA any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-20927
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a device initiates SSL/TLS connections. An attacker could exploit this vulnerability by ensuring that the device will connect to an SSL/TLS server that is using specific encryption parameters. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.
Published 2022-11-10 · Modified
7.7EPSS 0.005
CVE-2022-20918
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated, remote attacker to perform an SNMP GET request using a default credential. This vulnerability is due to the presence of a default credential for SNMP version 1 (SNMPv1) and SNMP version 2 (SNMPv2). An attacker could exploit this vulnerability by sending an SNMPv1 or SNMPv2 GET request to an affected device. A successful exploit could allow the attacker to retrieve sensitive information from the device using the default credential. This attack will only be successful if SNMP is configured, and the attacker can only perform SNMP GET requests; write access using SNMP is not allowed.
Published 2022-11-10 · Modified
7.5EPSS 0.009
CVE-2019-1978
Cisco Firepower Threat Defense Software Stream Reassembly Bypass Vulnerability
Published 2019-11-05 · Modified
5.81 PoCEPSS 0.094
CVE-2019-1981
Cisco Firepower Threat Defense Software NULL Character Obfuscation Detection Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2019-1980
Cisco Firepower Threat Defense Software Nonstandard Protocol Detection Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2019-1982
Cisco Firepower Threat Defense Software HTTP Filtering Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010