VendorsCiscosecure_firewall_threat_defenseany version
Vulnerabilities

Cisco Secure Firewall Threat Defense (FTD) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2022-20745
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.015
CVE-2020-3528
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPFv2 Link-Local Signaling Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.014
CVE-2021-34792
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Resource Exhaustion Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2020-3563
Cisco Firepower Threat Defense Software TCP Flood Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.014
CVE-2021-34781
Cisco Firepower Threat Defense Software SSH Connections Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2021-40116
Multiple Cisco Products Snort Rule Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2021-1402
Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
Published 2021-04-29 · Modified
8.6EPSS 0.014
CVE-2020-3571
Cisco Firepower 4110 ICMP Flood Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.014
CVE-2021-40118
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Denial of Service Vulnerabilities
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2022-20746
Cisco Firepower Threat Defense Software TCP Proxy Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.013
CVE-2022-20715
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.013
CVE-2022-20751
Cisco Firepower Threat Defense Software Snort Out of Memory Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.013
CVE-2021-1501
Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software SIP Denial of Service Vulnerability
Published 2021-04-29 · Modified
8.6EPSS 0.013
CVE-2021-1573
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
Published 2022-01-11 · Modified
8.6EPSS 0.013
CVE-2021-34704
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
Published 2022-01-11 · Modified
8.6EPSS 0.013
CVE-2022-20757
Cisco Firepower Threat Defense Software Denial of Service Vulnerability
Published 2022-05-03 · Modified
8.6EPSS 0.012
CVE-2022-20946
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory handling error that occurs when GRE traffic is processed. An attacker could exploit this vulnerability by sending a crafted GRE payload through an affected device. A successful exploit could allow the attacker to cause the device to restart, resulting in a DoS condition. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM"] This advisory is part of the November 2022 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication.
Published 2022-11-10 · Modified
8.6EPSS 0.009
CVE-2023-20083
A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of service (DoS) condition. FTD management traffic is not affected by this vulnerability. This vulnerability is due to improper error checking when parsing fields within the ICMPv6 header. An attacker could exploit this vulnerability by sending a crafted ICMPv6 packet through an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition. Note: To recover from the DoS condition, the Snort 2 Detection Engine or the Cisco FTD device may need to be restarted.
Published 2023-11-01 · Modified
8.6EPSS 0.007
CVE-2021-34793
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.006
CVE-2024-20342
Cisco Firepower Threat Defense Software Rate Filter Bypass Vulnerability
Published 2024-10-23 · Analyzed
8.6EPSS 0.005
CVE-2026-20039
Cisco Adaptive Security Appliance and Firepower Threat Defense Software SSL VPN Authentication Denial of Service Vulnerability
Published 2026-03-04 · Analyzed
8.6EPSS 0.004
CVE-2026-20101
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messages to the SAML service. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
8.6EPSS 0.004
CVE-2026-20103
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access SSL VPN connections. This does not affect the management interface, though it may become temporarily unresponsive. This vulnerability is due to trusting user input without validation. An attacker could exploit this vulnerability by sending crafted packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device web interface to stop responding, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
8.6EPSS 0.004
CVE-2021-1493
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Buffer Overflow Denial of Service Vulnerability
Published 2021-04-29 · Modified
8.5EPSS 0.012
CVE-2019-12674
Cisco Firepower Threat Defense Software Multi-instance Container Escape Vulnerabilities
Published 2019-10-02 · Modified
8.2EPSS 0.008
CVE-2023-20063
Cisco Cisco Firepower Threat Defense Software and Cisco Firepower Management Center Code Injection Vulnerability
Published 2023-11-01 · Modified
8.2EPSS 0.004
CVE-2020-3514
Cisco Firepower Threat Defense Software Multi-Instance Container Escape Vulnerability
Published 2020-10-21 · Modified
8.2EPSS 0.004
CVE-2020-3550
Cisco Firepower Management Center Software and Firepower Threat Defense Software Directory Traversal Vulnerability
Published 2020-10-21 · Modified
8.1EPSS 0.022
CVE-2021-34762
Cisco Firepower Management Center Software Authenticated Directory Traversal Vulnerability
Published 2021-10-27 · Modified
8.1EPSS 0.020
CVE-2020-3549
Cisco Firepower Management Center Software and Firepower Threat Defense Software sftunnel Pass the Hash Vulnerability
Published 2020-10-21 · Modified
8.1EPSS 0.010
CVE-2019-1687
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software TCP Proxy Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.029
CVE-2021-40114
Multiple Cisco Products Snort Memory Leak Denial of Service Vulnerability
Published 2021-10-27 · Modified
7.8EPSS 0.024
CVE-2019-1697
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Lightweight Directory Access Protocol Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.020
CVE-2019-12698
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN CPU Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.8EPSS 0.020
CVE-2020-3555
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SIP Denial of Service Vulnerability
Published 2020-10-21 · Modified
7.8EPSS 0.017
CVE-2020-3303
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IKEv1 Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2020-3305
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software BGP Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2020-3306
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DHCP Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2020-3167
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
Published 2020-02-26 · Modified
7.8EPSS 0.009
CVE-2021-1448
Cisco Firepower Threat Defense Software Command Injection Vulnerability
Published 2021-04-29 · Modified
7.8EPSS 0.003
← Prev2 / 5Next →