VendorsCiscosecure_firewall_threat_defenseall versions
Vulnerabilities

Cisco Secure Firewall Threat Defense (FTD)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

276CVEs
CVE-2020-3572
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Session Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.018
CVE-2019-12673
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software FTP Inspection Denial of Service Vulnerability
Published 2019-10-02 · Modified
8.6EPSS 0.018
CVE-2020-3533
Cisco Firepower Threat Defense Software SNMP Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.018
CVE-2022-20767
Cisco Firepower Threat Defense Software DNS Enforcement Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.017
CVE-2021-1504
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services VPN Denial of Service Vulnerabilities
Published 2021-04-29 · Modified
8.6EPSS 0.017
CVE-2021-1445
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services VPN Denial of Service Vulnerabilities
Published 2021-04-29 · Modified
8.6EPSS 0.017
CVE-2021-34783
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Software-Based SSL/TLS Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.016
CVE-2022-20760
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DNS Inspection Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.016
CVE-2021-40117
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.015
CVE-2022-20745
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.015
CVE-2020-3528
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPFv2 Link-Local Signaling Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.014
CVE-2021-34792
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Resource Exhaustion Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2020-3563
Cisco Firepower Threat Defense Software TCP Flood Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.014
CVE-2021-34781
Cisco Firepower Threat Defense Software SSH Connections Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2021-40116
Multiple Cisco Products Snort Rule Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2021-1402
Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
Published 2021-04-29 · Modified
8.6EPSS 0.014
CVE-2020-3571
Cisco Firepower 4110 ICMP Flood Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.014
CVE-2021-40118
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Denial of Service Vulnerabilities
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2022-20746
Cisco Firepower Threat Defense Software TCP Proxy Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.013
CVE-2022-20715
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.013
CVE-2022-20751
Cisco Firepower Threat Defense Software Snort Out of Memory Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.013
CVE-2021-1501
Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software SIP Denial of Service Vulnerability
Published 2021-04-29 · Modified
8.6EPSS 0.013
CVE-2021-1573
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
Published 2022-01-11 · Modified
8.6EPSS 0.013
CVE-2021-34704
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
Published 2022-01-11 · Modified
8.6EPSS 0.013
CVE-2019-1669
Cisco Firepower Threat Defense Software Packet Inspection and Enforcement Bypass Vulnerability
Published 2019-01-24 · Modified
8.6EPSS 0.012
CVE-2022-20757
Cisco Firepower Threat Defense Software Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.012
CVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
Published 2026-08-11 · Analyzed
8.6KEVEPSS 0.010
CVE-2022-20946
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory handling error that occurs when GRE traffic is processed. An attacker could exploit this vulnerability by sending a crafted GRE payload through an affected device. A successful exploit could allow the attacker to cause the device to restart, resulting in a DoS condition. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM"] This advisory is part of the November 2022 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication.
Published 2022-11-10 · Modified
8.6EPSS 0.009
CVE-2022-20947
A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper processing of HostScan data received from the Posture (HostScan) module. An attacker could exploit this vulnerability by sending crafted HostScan data to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-dap-dos-GhYZBxDU ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-dap-dos-GhYZBxDU"] This advisory is part of the November 2022 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication.
Published 2022-11-10 · Modified
8.6EPSS 0.009
CVE-2023-20006
A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to an implementation error within the cryptographic functions for SSL/TLS traffic processing when they are offloaded to the hardware. An attacker could exploit this vulnerability by sending a crafted stream of SSL/TLS traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected error in the hardware-based cryptography engine, which could cause the device to reload.
Published 2023-06-28 · Modified
8.6EPSS 0.009
CVE-2023-20244
A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain packets when they are sent to the inspection engine. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to deplete all 9,472 byte blocks on the device, resulting in traffic loss across the device or an unexpected reload of the device. If the device does not reload on its own, a manual reload of the device would be required to recover from this state.
Published 2023-11-01 · Modified
8.6EPSS 0.008
CVE-2024-20351
Cisco Firepower Threat Defense Software Snort Firewall Denial of Service Vulnerability
Published 2024-10-23 · Analyzed
8.6EPSS 0.007
CVE-2024-20339
Cisco Firepower Threat Defense Software for Firepower 2100 Series TLS Denial of Service Vulnerability
Published 2024-10-23 · Analyzed
8.6EPSS 0.007
CVE-2023-20083
A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of service (DoS) condition. FTD management traffic is not affected by this vulnerability. This vulnerability is due to improper error checking when parsing fields within the ICMPv6 header. An attacker could exploit this vulnerability by sending a crafted ICMPv6 packet through an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition. Note: To recover from the DoS condition, the Snort 2 Detection Engine or the Cisco FTD device may need to be restarted.
Published 2023-11-01 · Modified
8.6EPSS 0.007
CVE-2023-20042
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handling process that can prevent the release of a session handler under specific conditions. An attacker could exploit this vulnerability by sending crafted SSL/TLS traffic to an affected device, increasing the probability of session handler leaks. A successful exploit could allow the attacker to eventually deplete the available session handler pool, preventing new sessions from being established and causing a DoS condition.
Published 2023-11-01 · Modified
8.6EPSS 0.007
CVE-2024-20330
Cisco Firepower Threat Defense Software for Cisco Firepower 2100 Series TCP UDP Snort 2 and Snort 2 Denial of Service Vulnerability
Published 2024-10-23 · Analyzed
8.6EPSS 0.007
CVE-2023-20086
A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of ICMPv6 messages. An attacker could exploit this vulnerability by sending crafted ICMPv6 messages to a targeted Cisco ASA or FTD system with IPv6 enabled. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2023-11-01 · Modified
8.6EPSS 0.007
CVE-2023-20095
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of HTTPS requests. An attacker could exploit this vulnerability by sending crafted HTTPS requests to an affected system. A successful exploit could allow the attacker to cause resource exhaustion, resulting in a DoS condition.
Published 2023-11-01 · Modified
8.6EPSS 0.006
CVE-2021-34793
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.006
CVE-2025-20182
Cisco Adaptive Security Appliance Software, Firepower Threat Defense Software and IOS XE Software IKEv2 Denial of Service Vulnerability
Published 2025-05-07 · Analyzed
8.6EPSS 0.005
← Prev2 / 7Next →