VendorsCiscosecure_firewall_threat_defenseall versions
Vulnerabilities

Cisco Secure Firewall Threat Defense (FTD)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

276CVEs
CVE-2024-20402
A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a logic error in memory management when the device is handling SSL VPN connections. An attacker could exploit this vulnerability by sending crafted SSL/TLS packets to the SSL VPN server of the affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2024-10-23 · Analyzed
8.6EPSS 0.005
CVE-2024-20426
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted IKEv2 traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2024-10-23 · Analyzed
8.6EPSS 0.005
CVE-2024-20495
A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation of client key data after the TLS session is established. An attacker could exploit this vulnerability by sending a crafted key value to an affected system over the secure TLS session. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2024-10-23 · Analyzed
8.6EPSS 0.005
CVE-2024-20494
A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper data validation during the TLS 1.3 handshake. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Note: This vulnerability can also impact the integrity of a device by causing VPN HostScan communication failures or file transfer failures when Cisco ASA Software is upgraded using Cisco Adaptive Security Device Manager (ASDM).
Published 2024-10-23 · Analyzed
8.6EPSS 0.005
CVE-2024-20342
Cisco Firepower Threat Defense Software Rate Filter Bypass Vulnerability
Published 2024-10-23 · Analyzed
8.6EPSS 0.005
CVE-2026-20039
Cisco Adaptive Security Appliance and Firepower Threat Defense Software SSL VPN Authentication Denial of Service Vulnerability
Published 2026-03-04 · Analyzed
8.6EPSS 0.004
CVE-2026-20101
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messages to the SAML service. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
8.6EPSS 0.004
CVE-2026-20012
A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper parsing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit of Cisco IOS Software and IOS XE Software could allow the attacker to cause the affected device to reload, resulting in a DoS condition. A successful exploit of Cisco Secure Firewall ASA Software and Secure FTD Software could allow the attacker to partially exhaust system memory, resulting in system instability, such as the inability to establish new IKEv2 VPN sessions. A manual reboot of the device is required to recover from this condition.
Published 2026-03-25 · Analyzed
8.6EPSS 0.004
CVE-2026-20103
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access SSL VPN connections. This does not affect the management interface, though it may become temporarily unresponsive. This vulnerability is due to trusting user input without validation. An attacker could exploit this vulnerability by sending crafted packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device web interface to stop responding, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
8.6EPSS 0.004
CVE-2021-1493
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Buffer Overflow Denial of Service Vulnerability
Published 2021-04-29 · Modified
8.5EPSS 0.012
CVE-2019-12674
Cisco Firepower Threat Defense Software Multi-instance Container Escape Vulnerabilities
Published 2019-10-02 · Modified
8.2EPSS 0.008
CVE-2023-20063
Cisco Cisco Firepower Threat Defense Software and Cisco Firepower Management Center Code Injection Vulnerability
Published 2023-11-01 · Modified
8.2EPSS 0.004
CVE-2018-0453
Cisco Firepower Management Center and Firepower System Software Sourcefire Tunnel Control Channel Command Execution Vulnerability
Published 2018-10-05 · Modified
8.2EPSS 0.004
CVE-2020-3514
Cisco Firepower Threat Defense Software Multi-Instance Container Escape Vulnerability
Published 2020-10-21 · Modified
8.2EPSS 0.004
CVE-2020-3550
Cisco Firepower Management Center Software and Firepower Threat Defense Software Directory Traversal Vulnerability
Published 2020-10-21 · Modified
8.1EPSS 0.022
CVE-2021-34762
Cisco Firepower Management Center Software Authenticated Directory Traversal Vulnerability
Published 2021-10-27 · Modified
8.1EPSS 0.020
CVE-2020-3549
Cisco Firepower Management Center Software and Firepower Threat Defense Software sftunnel Pass the Hash Vulnerability
Published 2020-10-21 · Modified
8.1EPSS 0.010
CVE-2019-1687
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software TCP Proxy Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.029
CVE-2018-15383
Cisco Adaptive Security Appliance Direct Memory Access Denial of Service Vulnerability
Published 2018-10-05 · Modified
7.8EPSS 0.025
CVE-2021-40114
Multiple Cisco Products Snort Memory Leak Denial of Service Vulnerability
Published 2021-10-27 · Modified
7.8EPSS 0.024
CVE-2017-6632
A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging of certain TCP packets by the affected software. An attacker could exploit this vulnerability by sending a flood of crafted TCP packets to an affected device. A successful exploit could allow the attacker to cause a DoS condition. The success of an exploit is dependent on how an administrator has configured logging for SSL policies for a device. This vulnerability affects Cisco FirePOWER System Software that is configured to log connections by using SSL policy default actions. Cisco Bug IDs: CSCvd07072.
Published 2017-05-22 · Modified
7.8EPSS 0.024
CVE-2019-1697
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Lightweight Directory Access Protocol Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.020
CVE-2019-12698
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN CPU Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.8EPSS 0.020
CVE-2020-3555
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SIP Denial of Service Vulnerability
Published 2020-10-21 · Modified
7.8EPSS 0.017
CVE-2020-3303
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IKEv1 Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2020-3305
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software BGP Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2020-3306
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DHCP Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.012
CVE-2020-3167
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
Published 2020-02-26 · Modified
7.8EPSS 0.009
CVE-2019-1709
Cisco Firepower Threat Defense Software Command Injection Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.007
CVE-2021-1448
Cisco Firepower Threat Defense Software Command Injection Vulnerability
Published 2021-04-29 · Modified
7.8EPSS 0.003
CVE-2021-34755
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
Published 2021-10-27 · Modified
7.8EPSS 0.003
CVE-2021-34756
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
Published 2021-10-27 · Modified
7.8EPSS 0.003
CVE-2022-20729
Cisco Firepower Threat Defense Software XML Injection Vulnerability
Published 2022-05-03 · Modified
7.8EPSS 0.003
CVE-2019-1693
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.7EPSS 0.020
CVE-2019-12700
Cisco FTD, FMC, and FXOS Software Pluggable Authentication Module Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.7EPSS 0.019
CVE-2021-1422
Cisco Adaptive Security Appliance Software Release 9.16.1 and Cisco Firepower Threat Defense Software Release 7.0.0 IPsec Denial of Service Vulnerability
Published 2021-07-16 · Modified
7.7EPSS 0.012
CVE-2022-20924
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Published 2022-11-10 · Modified
7.7EPSS 0.008
CVE-2025-20127
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 3100 and 4200 Series TLS Cipher Denial of Service Vulnerability
Published 2025-08-14 · Analyzed
7.7EPSS 0.007
CVE-2024-20268
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SNMP Denial of Service Vulnerability
Published 2024-10-23 · Analyzed
7.7EPSS 0.006
CVE-2022-20927
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a device initiates SSL/TLS connections. An attacker could exploit this vulnerability by ensuring that the device will connect to an SSL/TLS server that is using specific encryption parameters. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.
Published 2022-11-10 · Modified
7.7EPSS 0.005
← Prev3 / 7Next →