Vulnerabilities > Cisco > Adaptive Security Appliance Software > 9.8.2.45

DATE CVE VULNERABILITY TITLE RISK
2024-10-23 CVE-2024-20481 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Firepower Threat Defense Software
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion.
network
low complexity
cisco CWE-772
5.8
2024-10-23 CVE-2024-20485 Code Injection vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges.
local
low complexity
cisco CWE-94
6.7
2024-10-23 CVE-2024-20493 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Firepower Threat Defense Software
A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in a temporary denial of service (DoS) condition. This vulnerability is due to ineffective handling of memory resources during the authentication process.
network
low complexity
cisco CWE-772
5.3
2024-10-23 CVE-2024-20331 Insufficient Entropy vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent users from authenticating. This vulnerability is due to insufficient entropy in the authentication process.
network
high complexity
cisco CWE-331
5.9
2024-10-23 CVE-2024-20341 Cross-site Scripting vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device.
network
low complexity
cisco CWE-79
6.1
2023-03-23 CVE-2023-20081 Out-of-bounds Write vulnerability in Cisco products
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
high complexity
cisco CWE-787
5.9
2022-05-03 CVE-2022-20715 Improper Input Validation vulnerability in Cisco Firepower Threat Defense
A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
8.6
2022-05-03 CVE-2022-20737 Out-of-bounds Write vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device or to obtain portions of process memory from an affected device.
network
low complexity
cisco CWE-787
7.1
2022-05-03 CVE-2022-20742 Unspecified vulnerability in Cisco Firepower Threat Defense
A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel.
network
high complexity
cisco
7.4
2022-05-03 CVE-2022-20745 Improper Input Validation vulnerability in Cisco Firepower Threat Defense
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5