target entity

Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

6 source-linked records in the current knowledge graph.

high

CVE-2024-20481: Cisco ASA and FTD Denial-of-Service Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20481EPSS 16.0%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20359: Cisco ASA and FTD Privilege Escalation Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20359EPSS 19.4%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20353: Cisco ASA and FTD Denial of Service Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20353EPSS 70.7%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3259: Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-3259EPSS 71.8%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3452: Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. Required action: Apply updates per vendor instructions.

CVE-2020-3452EPSS 100.0%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3580: Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. Required action: Apply updates per vendor instructions.

CVE-2020-3580EPSS 85.4%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution