Vulnerabilities > Cisco > Firepower Threat Defense

DATE CVE VULNERABILITY TITLE RISK
2019-02-21 CVE-2019-1691 Improper Handling of Exceptional Conditions vulnerability in Cisco Firepower Threat Defense
A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT detection engine, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
5.8
2019-01-24 CVE-2019-1669 Protection Mechanism Failure vulnerability in Cisco Firepower Threat Defense 6.3.0/6.4.0
A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-693
8.6
2018-11-01 CVE-2018-15454 Improper Input Validation vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6
2018-10-05 CVE-2018-15399 Allocation of Resources Without Limits or Throttling vulnerability in Cisco products
A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affected device, resulting in a denial of service (DoS) condition.
network
high complexity
cisco CWE-770
6.8
2018-10-05 CVE-2018-15398 Unspecified vulnerability in Cisco products
A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an affected device.
network
high complexity
cisco
4.0
2018-10-05 CVE-2018-15390 Improper Locking vulnerability in Cisco Firepower Threat Defense
A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
network
high complexity
cisco CWE-667
6.8
2018-10-05 CVE-2018-15383 Allocation of Resources Without Limits or Throttling vulnerability in Cisco products
A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition.
network
low complexity
cisco CWE-770
7.5
2018-10-05 CVE-2018-0453 OS Command Injection vulnerability in Cisco Firepower Threat Defense
A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with root privileges on the Cisco Firepower Management Center (FMC), or through Cisco FMC on other Firepower sensors and devices that are controlled by the same Cisco FMC.
local
low complexity
cisco CWE-78
8.2
2018-06-07 CVE-2018-0296 Path Traversal vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-22
7.5
2018-05-17 CVE-2018-0297 Protection Mechanism Failure vulnerability in Cisco Firepower Threat Defense
A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic.
network
low complexity
cisco CWE-693
5.8