VendorsCiscosecure_firewall_threat_defenseall versions
Vulnerabilities

Cisco Secure Firewall Threat Defense (FTD)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

276CVEs
CVE-2024-20408
A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need valid remote access VPN user credentials on the affected device. This vulnerability is due to improper validation of data in HTTPS POST requests. An attacker could exploit this vulnerability by sending a crafted HTTPS POST request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
Published 2024-10-23 · Analyzed
7.7EPSS 0.004
CVE-2026-20105
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaust device memory resulting in a denial of service (DoS) condition.This does not affect the management or MUS interfaces. This vulnerability is due to trusting user input without validation. An attacker could exploit this vulnerability by sending crafted packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
7.7EPSS 0.003
CVE-2026-20049
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the affected device.
Published 2026-03-04 · Analyzed
7.7EPSS 0.003
CVE-2026-20014
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to the improper processing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted, authenticated IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust memory, causing the device to reload.
Published 2026-03-04 · Analyzed
7.7EPSS 0.003
CVE-2026-20100
A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This does not affect the management or MUS interfaces. This vulnerability is due to trusting user input without validation in the LUA interprerter. An attacker could exploit this vulnerability by sending crafted HTTP packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
7.7EPSS 0.003
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2020-3452
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
Published 2020-07-22 · Analyzed
7.5KEV3 PoCEPSS 1.000
CVE-2018-0296
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.
Published 2018-06-07 · Analyzed
7.5KEV2 PoCEPSS 0.999
CVE-2020-3259
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
Published 2020-05-06 · Analyzed
7.5KEVEPSS 0.718
CVE-2022-20866
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability
Published 2022-08-10 · Modified
7.5EPSS 0.174
CVE-2019-1704
Cisco Firepower Threat Defense Software SMB Protocol Preprocessor Detection Engine Denial of Service Vulnerabilities
Published 2019-05-03 · Modified
7.5EPSS 0.022
CVE-2018-0227
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification of the SSL Client Certificate. An attacker could exploit this vulnerability by connecting to the ASA VPN without a proper private key and certificate pair. A successful exploit could allow the attacker to establish an SSL VPN connection to the ASA when the connection should have been rejected. This vulnerability affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliances (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliances (ASAv), Firepower 4110 Security Appliances, Firepower 9300 ASA Security Modules. Cisco Bug IDs: CSCvg40155.
Published 2018-04-19 · Modified
7.5EPSS 0.020
CVE-2021-1223
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
Published 2021-01-13 · Modified
7.5EPSS 0.020
CVE-2020-3255
Cisco Firepower Threat Defense Software Packet Flood Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.5EPSS 0.018
CVE-2019-1696
Cisco Firepower Threat Defense Software SMB Protocol Preprocessor Detection Engine Denial of Service Vulnerabilities
Published 2019-05-03 · Modified
7.5EPSS 0.018
CVE-2019-1715
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
Published 2019-05-03 · Modified
7.5EPSS 0.017
CVE-2019-1970
Cisco Firepower Threat Defense Software File Policy Bypass Vulnerability
Published 2019-08-08 · Modified
7.5EPSS 0.015
CVE-2022-20685
Multiple Cisco Products Snort Modbus Denial of Service Vulnerability
Published 2024-11-15 · Analyzed
7.5EPSS 0.014
CVE-2019-12627
Cisco Firepower Threat Defense Software Information Disclosure Vulnerability
Published 2019-08-21 · Modified
7.5EPSS 0.012
CVE-2021-34754
Cisco Firepower Threat Defense Software Ethernet Industrial Protocol Policy Bypass Vulnerabilities
Published 2021-10-27 · Modified
7.5EPSS 0.010
CVE-2022-20730
Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability
Published 2022-05-03 · Modified
7.5EPSS 0.010
CVE-2020-3317
Cisco Firepower Threat Defense Software SSL Input Validation Denial of Service Vulnerability
Published 2020-10-21 · Modified
7.5EPSS 0.010
CVE-2022-20854
A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when an SSH session fails to be established. An attacker could exploit this vulnerability by sending a high rate of crafted SSH connections to the instance. A successful exploit could allow the attacker to cause resource exhaustion, resulting in a reboot on the affected device.
Published 2022-11-10 · Modified
7.5EPSS 0.009
CVE-2023-20107
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
Published 2023-03-23 · Modified
7.5EPSS 0.007
CVE-2022-20795
Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense Software AnyConnect SSL VPN Denial of Service Vulnerability
Published 2022-04-21 · Modified
7.5EPSS 0.007
CVE-2019-12676
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPF LSA Processing Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.4EPSS 0.005
CVE-2022-20742
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPsec IKEv2 VPN Information Disclosure Vulnerability
Published 2022-05-03 · Modified
7.4EPSS 0.005
CVE-2020-3334
Cisco Firepower 2100 Series Security Appliances ARP Denial of Service Vulnerability
Published 2020-05-06 · Modified
7.4EPSS 0.004
CVE-2020-3577
Cisco Firepower Threat Defense Software Inline Pair/Passive Mode Denial of Service Vulnerability
Published 2020-10-21 · Modified
7.4EPSS 0.004
CVE-2019-12694
Cisco Firepower Threat Defense Software Command Injection Vulnerability
Published 2019-10-02 · Modified
7.2EPSS 0.008
CVE-2021-1476
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Command Injection Vulnerability
Published 2021-04-29 · Modified
7.2EPSS 0.005
CVE-2020-3253
Cisco Firepower Threat Defense Software Shell Access Vulnerability
Published 2020-05-06 · Modified
7.2EPSS 0.003
CVE-2021-1488
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000 and 2100 Series Appliances Command Injection Vulnerability
Published 2021-04-29 · Modified
7.2EPSS 0.003
CVE-2018-15399
Cisco Adaptive Security Appliance TCP Syslog Denial of Service Vulnerability
Published 2018-10-05 · Modified
7.1EPSS 0.018
CVE-2017-6625
A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access control policy of Cisco Firepower System Software could allow an authenticated, remote attacker to cause an affected system to stop inspecting and processing packets, resulting in a denial of service (DoS) condition. The vulnerability is due to improper SSL policy handling by the affected software when packets are passed through the sensing interfaces of an affected system. An attacker could exploit this vulnerability by sending crafted packets through a targeted system. This vulnerability affects Cisco Firepower System Software that is configured with the SSL policy feature. Cisco Bug IDs: CSCvc84361.
Published 2017-05-03 · Modified
7.1EPSS 0.018
CVE-2018-15390
Cisco Firepower Threat Defense Software FTP Inspection Denial of Service Vulnerability
Published 2018-10-05 · Modified
7.1EPSS 0.011
CVE-2023-20081
Cisco Adaptive Security Appliance Software, Firepower Threat Defense Software, IOS Software, and IOS XE Software IPv6 DHCP (DHCPv6) Client Denial of Service Vulnerability
Published 2023-03-23 · Modified
6.8EPSS 0.007
CVE-2024-20331
Cisco Adaptive Security Appliance and Firepower Threat Defense Software VPN Authentication DoS Vulnerability
Published 2024-10-23 · Analyzed
6.8EPSS 0.007
CVE-2026-20050
Cisco Secure Firewall Threat Defense Decryption Policy Denial of Service Vulnerability
Published 2026-03-04 · Analyzed
6.8EPSS 0.004
CVE-2022-20826
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This vulnerability is due to a logic error in the boot process. An attacker could exploit this vulnerability by injecting malicious code into a specific memory location during the boot process of an affected device. A successful exploit could allow the attacker to execute persistent code at boot time and break the chain of trust.
Published 2022-11-10 · Modified
6.8EPSS 0.003
← Prev4 / 7Next →