Vulnerabilities > Cisco > Firepower Threat Defense > High

DATE CVE VULNERABILITY TITLE RISK
2020-05-06 CVE-2020-3179 Double Free vulnerability in Cisco products
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-415
7.5
2020-02-26 CVE-2020-3167 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS).
local
low complexity
cisco CWE-78
7.8
2019-10-02 CVE-2019-15256 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
8.6
2019-10-02 CVE-2019-12699 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges.
local
low complexity
cisco CWE-78
7.8
2019-10-02 CVE-2019-12698 Unspecified vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device.
network
low complexity
cisco
7.5
2019-10-02 CVE-2019-12678 Integer Underflow (Wrap or Wraparound) vulnerability in Cisco products
A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-191
7.5
2019-10-02 CVE-2019-12676 Unspecified vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition.
low complexity
cisco
7.4
2019-10-02 CVE-2019-12675 Improper Encoding or Escaping of Output vulnerability in Cisco products
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace.
local
low complexity
cisco CWE-116
8.8
2019-10-02 CVE-2019-12674 Improper Encoding or Escaping of Output vulnerability in Cisco products
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace.
local
low complexity
cisco CWE-116
8.2
2019-10-02 CVE-2019-12673 Improper Input Validation vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5