VendorsCiscosecure_firewall_threat_defenseany version
Vulnerabilities

Cisco Secure Firewall Threat Defense (FTD) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2021-34756
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
Published 2021-10-27 · Modified
7.8EPSS 0.003
CVE-2021-34755
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
Published 2021-10-27 · Modified
7.8EPSS 0.003
CVE-2022-20729
Cisco Firepower Threat Defense Software XML Injection Vulnerability
Published 2022-05-03 · Modified
7.8EPSS 0.003
CVE-2019-1693
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Denial of Service Vulnerability
Published 2019-05-03 · Modified
7.7EPSS 0.020
CVE-2019-12700
Cisco FTD, FMC, and FXOS Software Pluggable Authentication Module Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.7EPSS 0.019
CVE-2022-20927
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a device initiates SSL/TLS connections. An attacker could exploit this vulnerability by ensuring that the device will connect to an SSL/TLS server that is using specific encryption parameters. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.
Published 2022-11-10 · Modified
7.7EPSS 0.005
CVE-2026-20105
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaust device memory resulting in a denial of service (DoS) condition.This does not affect the management or MUS interfaces. This vulnerability is due to trusting user input without validation. An attacker could exploit this vulnerability by sending crafted packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
7.7EPSS 0.003
CVE-2026-20049
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the affected device.
Published 2026-03-04 · Analyzed
7.7EPSS 0.003
CVE-2026-20014
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to the improper processing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted, authenticated IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust memory, causing the device to reload.
Published 2026-03-04 · Analyzed
7.7EPSS 0.003
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2020-3452
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
Published 2020-07-22 · Analyzed
7.5KEV3 PoCEPSS 1.000
CVE-2018-0296
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.
Published 2018-06-07 · Analyzed
7.5KEV2 PoCEPSS 0.999
CVE-2020-3259
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
Published 2020-05-06 · Analyzed
7.5KEVEPSS 0.718
CVE-2022-20866
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability
Published 2022-08-10 · Modified
7.5EPSS 0.174
CVE-2019-1704
Cisco Firepower Threat Defense Software SMB Protocol Preprocessor Detection Engine Denial of Service Vulnerabilities
Published 2019-05-03 · Modified
7.5EPSS 0.022
CVE-2018-0227
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification of the SSL Client Certificate. An attacker could exploit this vulnerability by connecting to the ASA VPN without a proper private key and certificate pair. A successful exploit could allow the attacker to establish an SSL VPN connection to the ASA when the connection should have been rejected. This vulnerability affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliances (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliances (ASAv), Firepower 4110 Security Appliances, Firepower 9300 ASA Security Modules. Cisco Bug IDs: CSCvg40155.
Published 2018-04-19 · Modified
7.5EPSS 0.020
CVE-2021-1223
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
Published 2021-01-13 · Modified
7.5EPSS 0.020
CVE-2020-3255
Cisco Firepower Threat Defense Software Packet Flood Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.5EPSS 0.018
CVE-2019-1696
Cisco Firepower Threat Defense Software SMB Protocol Preprocessor Detection Engine Denial of Service Vulnerabilities
Published 2019-05-03 · Modified
7.5EPSS 0.018
CVE-2019-1715
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
Published 2019-05-03 · Modified
7.5EPSS 0.017
CVE-2019-1970
Cisco Firepower Threat Defense Software File Policy Bypass Vulnerability
Published 2019-08-08 · Modified
7.5EPSS 0.015
CVE-2019-12627
Cisco Firepower Threat Defense Software Information Disclosure Vulnerability
Published 2019-08-21 · Modified
7.5EPSS 0.012
CVE-2021-34754
Cisco Firepower Threat Defense Software Ethernet Industrial Protocol Policy Bypass Vulnerabilities
Published 2021-10-27 · Modified
7.5EPSS 0.010
CVE-2022-20730
Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability
Published 2022-05-03 · Modified
7.5EPSS 0.010
CVE-2020-3317
Cisco Firepower Threat Defense Software SSL Input Validation Denial of Service Vulnerability
Published 2020-10-21 · Modified
7.5EPSS 0.010
CVE-2022-20854
A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when an SSH session fails to be established. An attacker could exploit this vulnerability by sending a high rate of crafted SSH connections to the instance. A successful exploit could allow the attacker to cause resource exhaustion, resulting in a reboot on the affected device.
Published 2022-11-10 · Modified
7.5EPSS 0.009
CVE-2023-20107
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
Published 2023-03-23 · Modified
7.5EPSS 0.007
CVE-2022-20795
Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense Software AnyConnect SSL VPN Denial of Service Vulnerability
Published 2022-04-21 · Modified
7.5EPSS 0.007
CVE-2019-12676
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPF LSA Processing Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.4EPSS 0.005
CVE-2022-20742
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPsec IKEv2 VPN Information Disclosure Vulnerability
Published 2022-05-03 · Modified
7.4EPSS 0.005
CVE-2020-3334
Cisco Firepower 2100 Series Security Appliances ARP Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.4EPSS 0.004
CVE-2020-3577
Cisco Firepower Threat Defense Software Inline Pair/Passive Mode Denial of Service Vulnerability
Published 2020-10-21 · Modified
7.4EPSS 0.004
CVE-2019-12694
Cisco Firepower Threat Defense Software Command Injection Vulnerability
Published 2019-10-02 · Modified
7.2EPSS 0.008
CVE-2021-1476
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Command Injection Vulnerability
Published 2021-04-29 · Modified
7.2EPSS 0.005
CVE-2020-3253
Cisco Firepower Threat Defense Software Shell Access Vulnerability
Published 2020-05-06 · Modified
7.2EPSS 0.003
CVE-2021-1488
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000 and 2100 Series Appliances Command Injection Vulnerability
Published 2021-04-29 · Modified
7.2EPSS 0.003
CVE-2018-15390
Cisco Firepower Threat Defense Software FTP Inspection Denial of Service Vulnerability
Published 2018-10-05 · Modified
7.1EPSS 0.011
CVE-2026-20050
Cisco Secure Firewall Threat Defense Decryption Policy Denial of Service Vulnerability
Published 2026-03-04 · Analyzed
6.8EPSS 0.004
CVE-2026-20025
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key. This vulnerability is due to insufficient input validation when processing OSPF link-state update (LSU) packets. An attacker could exploit this vulnerability by sending crafted OSPF LSU packets. A successful exploit could allow the attacker to corrupt the heap, causing the device to reload, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
6.8EPSS 0.002
CVE-2026-20016
A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the attacker must have valid administrative credentials on an affected device. This vulnerability is due to insufficient input validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input for specific CLI commands. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
Published 2026-03-04 · Analyzed
6.7EPSS 0.003
← Prev3 / 5Next →