Vulnerabilities > Cisco > Adaptive Security Appliance Software > 9.8.4.8

DATE CVE VULNERABILITY TITLE RISK
2020-02-26 CVE-2020-3167 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS).
local
low complexity
cisco CWE-78
7.8
2020-02-26 CVE-2020-3166 Improper Input Validation vulnerability in Cisco Firepower Threat Defense
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS).
local
low complexity
cisco CWE-20
6.7
2019-10-02 CVE-2019-12698 Unspecified vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device.
network
low complexity
cisco
7.5
2019-10-02 CVE-2019-12695 Cross-site Scripting vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1
2019-10-02 CVE-2019-12673 Improper Input Validation vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5