VendorsCiscosecure_firewall_threat_defenseany version
Vulnerabilities

Cisco Secure Firewall Threat Defense (FTD) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2020-3458
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000/2100 Series Appliances Secure Boot Bypass Vulnerabilities
Published 2020-10-21 · Modified
6.7EPSS 0.003
CVE-2022-20934
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.
Published 2022-11-10 · Modified
6.7EPSS 0.003
CVE-2020-3166
Cisco FXOS Software CLI Arbitrary File Read and Write Vulnerability
Published 2020-02-26 · Modified
6.7EPSS 0.003
CVE-2021-34761
Cisco Firepower Threat Defense Software CLI Arbitrary File Write Vulnerability
Published 2021-10-27 · Modified
6.6EPSS 0.002
CVE-2020-3578
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Portal Access Rule Bypass Vulnerability
Published 2020-10-21 · Modified
6.5EPSS 0.012
CVE-2021-40125
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IKEv2 Site-to-Site VPN Denial of Service Vulnerability
Published 2021-10-27 · Modified
6.5EPSS 0.010
CVE-2022-20949
A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with high privileges to execute configuration commands on an affected system. This vulnerability exists because access to HTTPS endpoints is not properly restricted on an affected device. An attacker could exploit this vulnerability by sending specific messages to the affected HTTPS handler. A successful exploit could allow the attacker to perform configuration changes on the affected system, which should be configured and managed only through Cisco Firepower Management Center (FMC) Software.
Published 2022-11-10 · Modified
6.5EPSS 0.007
CVE-2019-1695
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Layer 2 Filtering Bypass Vulnerability
Published 2019-05-03 · Modified
6.5EPSS 0.007
CVE-2020-3580
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Published 2020-10-21 · Analyzed
6.1KEVEPSS 0.856
CVE-2020-3581
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Published 2020-10-21 · Modified
6.1EPSS 0.012
CVE-2020-3582
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Published 2020-10-21 · Modified
6.1EPSS 0.012
CVE-2020-3583
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Published 2020-10-21 · Modified
6.1EPSS 0.011
CVE-2019-12695
Cisco Adaptive Security Appliance and Firepower Threat Defense Software WebVPN Cross-Site Scripting Vulnerability
Published 2019-10-02 · Modified
6.1EPSS 0.011
CVE-2021-34764
Cisco Firepower Management Center Software Cross-Site Scripting and Open Redirect Vulnerabilities
Published 2021-10-27 · Modified
6.1EPSS 0.006
CVE-2026-20102
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting Vulnerability
Published 2026-03-04 · Analyzed
6.1EPSS 0.003
CVE-2021-1256
Cisco Firepower Threat Defense Software Command File Overwrite Vulnerability
Published 2021-04-29 · Modified
6.0EPSS 0.005
CVE-2026-20017
Cisco Secure FTD Software Authenticated Command Injection Vulnerability
Published 2026-03-04 · Analyzed
6.0EPSS 0.002
CVE-2026-20008
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
Published 2026-03-04 · Analyzed
6.0EPSS 0.001
CVE-2019-1978
Cisco Firepower Threat Defense Software Stream Reassembly Bypass Vulnerability
Published 2019-11-05 · Modified
5.81 PoCEPSS 0.094
CVE-2020-3299
Multiple Cisco Products SNORT HTTP Detection Engine File Policy Bypass Vulnerability
Published 2020-10-21 · Modified
5.8EPSS 0.023
CVE-2019-1691
Cisco Firepower Threat Defense Software SSL or TLS Denial of Service Vulnerability
Published 2019-02-21 · Modified
5.8EPSS 0.023
CVE-2020-3315
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
Published 2020-05-06 · Modified
5.8EPSS 0.022
CVE-2021-1224
Multiple Cisco Products Snort TCP Fast Open File Policy Bypass Vulnerability
Published 2021-01-13 · Modified
5.8EPSS 0.020
CVE-2021-1495
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
Published 2021-04-29 · Modified
5.8EPSS 0.017
CVE-2020-3285
Cisco Firepower Threat Defense Software SSL/TLS URL Category Bypass Vulnerability
Published 2020-05-06 · Modified
5.8EPSS 0.015
CVE-2020-3564
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software FTP Inspection Bypass Vulnerability
Published 2020-10-21 · Modified
5.8EPSS 0.013
CVE-2018-0243
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy that is intended to drop the Server Message Block Version 2 (SMB2) and SMB Version 3 (SMB3) protocols if malware is detected. The vulnerability is due to incorrect detection of an SMB2 or SMB3 file based on the total file length. An attacker could exploit this vulnerability by sending a crafted SMB2 or SMB3 transfer request through the targeted device. An exploit could allow the attacker to pass SMB2 or SMB3 files that could be malware even though the device is configured to block them. This vulnerability does not exist for SMB Version 1 (SMB1) files. This vulnerability affects Cisco Firepower System Software when one or more file action policies are configured, on software releases prior to 6.2.3. Cisco Bug IDs: CSCvg68807.
Published 2018-04-19 · Modified
5.8EPSS 0.012
CVE-2018-0244
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy to drop the Server Message Block (SMB) protocol if a malware file is detected. The vulnerability is due to how the SMB protocol handles a case in which a large file transfer fails. This case occurs when some pieces of the file are successfully transferred to the remote endpoint, but ultimately the file transfer fails and is reset. An attacker could exploit this vulnerability by sending a crafted SMB file transfer request through the targeted device. An exploit could allow the attacker to pass an SMB file that contains malware, which the device is configured to block. This vulnerability affects Cisco Firepower System Software when one or more file action policies are configured, on software releases prior to 6.2.3. Cisco Bug IDs: CSCvc20141.
Published 2018-04-19 · Modified
5.8EPSS 0.012
CVE-2019-1981
Cisco Firepower Threat Defense Software NULL Character Obfuscation Detection Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2019-1980
Cisco Firepower Threat Defense Software Nonstandard Protocol Detection Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2019-1982
Cisco Firepower Threat Defense Software HTTP Filtering Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2020-3565
Cisco Firepower Threat Defense Software TCP Intercept Bypass Vulnerability
Published 2020-10-21 · Modified
5.8EPSS 0.009
CVE-2021-34753
Cisco Firepower Threat Defense Ethernet Industrial Protocol Policy Bypass Vulnerabilities
Published 2024-11-15 · Analyzed
5.8EPSS 0.007
CVE-2023-20246
Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs when the access control policies are being populated. An attacker could exploit this vulnerability by establishing a connection to an affected device. A successful exploit could allow the attacker to bypass configured access control rules on the affected system.
Published 2023-11-01 · Modified
5.8EPSS 0.006
CVE-2023-20071
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.
Published 2023-11-01 · Modified
5.8EPSS 0.005
CVE-2024-20293
A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to a logic error that occurs when an ACL changes from inactive to active in the running configuration of an affected device. An attacker could exploit this vulnerability by sending traffic through the affected device that should be denied by the configured ACL. The reverse condition is also true—traffic that should be permitted could be denied by the configured ACL. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device, allowing the attacker to access trusted networks that the device might be protecting. Note: This vulnerability applies to both IPv4 and IPv6 traffic as well as dual-stack ACL configurations in which both IPv4 and IPv6 ACLs are configured on an interface.
Published 2024-05-22 · Analyzed
5.8EPSS 0.004
CVE-2026-20015
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network. This vulnerability is due to a memory leak when parsing IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to be manually reloaded.
Published 2026-03-04 · Analyzed
5.8EPSS 0.003
CVE-2026-20013
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to memory exhaustion caused by not freeing memory during IKEv2 packet processing. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to manually reload.
Published 2026-03-04 · Analyzed
5.8EPSS 0.003
CVE-2020-3352
Cisco Firepower Threat Defense Software Hidden Commands Vulnerability
Published 2020-10-21 · Modified
5.5EPSS 0.003
CVE-2021-1236
Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
Published 2021-01-13 · Modified
5.3EPSS 0.021
← Prev4 / 5Next →