VendorsCiscosecure_firewall_threat_defenseany version
Vulnerabilities

Cisco Secure Firewall Threat Defense (FTD) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2020-3188
Cisco Firepower Threat Defense Software Management Interface Denial of Service Vulnerability
Published 2020-05-06 · Modified
5.3EPSS 0.017
CVE-2020-3186
Cisco Firepower Threat Defense Software Management Access List Bypass Vulnerability
Published 2020-05-06 · Modified
5.3EPSS 0.014
CVE-2020-3585
Cisco Firepower 1000 Series Bleichenbacher Attack Vulnerability
Published 2020-10-21 · Modified
5.3EPSS 0.013
CVE-2021-34790
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Application Level Gateway Bypass Vulnerabilities
Published 2021-10-27 · Modified
5.3EPSS 0.011
CVE-2021-34791
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Application Level Gateway Bypass Vulnerabilities
Published 2021-10-27 · Modified
5.3EPSS 0.011
CVE-2021-34787
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Identity-Based Rule Bypass Vulnerability
Published 2021-10-27 · Modified
5.3EPSS 0.010
CVE-2021-34794
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SNMP Access Control Vulnerability
Published 2021-10-27 · Modified
5.3EPSS 0.009
CVE-2022-20940
A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption policies. An attacker could exploit this vulnerability by sending crafted TLS messages to an affected device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device.
Published 2022-11-10 · Modified
5.3EPSS 0.007
CVE-2023-20267
A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restriction. A successful exploit could allow the attacker to bypass location-based IP address restrictions.
Published 2023-11-01 · Modified
5.3EPSS 0.004
CVE-2026-20106
A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition requiring a manual reboot. This vulnerability is due to trusting user input without validation. An attacker could exploit this vulnerability by sending crafted packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a DoS condition.
Published 2026-03-04 · Analyzed
5.3EPSS 0.003
CVE-2020-3308
Cisco Firepower Threat Defense Software Signature Verification Bypass Vulnerability
Published 2020-05-06 · Modified
4.9EPSS 0.006
CVE-2019-1701
Cisco Adaptive Security Appliance and Firepower Threat Defense Software WebVPN Cross-Site Scripting Vulnerabilities
Published 2019-05-03 · Modified
4.8EPSS 0.009
CVE-2021-34763
Cisco Firepower Management Center Software Cross-Site Scripting and Open Redirect Vulnerabilities
Published 2021-10-27 · Modified
4.8EPSS 0.005
CVE-2020-3561
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN CRLF Injection Vulnerability
Published 2020-10-21 · Modified
4.7EPSS 0.013
CVE-2026-20069
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Client-Side Request Smuggling Vulnerability
Published 2026-03-04 · Analyzed
4.3EPSS 0.003
← Prev5 / 5