Vulnerabilities > Cisco > Firepower Threat Defense > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-23 CVE-2024-20388 Unspecified vulnerability in Cisco products
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses.
network
low complexity
cisco
5.3
2024-10-23 CVE-2024-20431 Unspecified vulnerability in Cisco Firepower Threat Defense
A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation data.
network
low complexity
cisco
5.8
2024-04-24 CVE-2024-20359 Code Injection vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges.
local
low complexity
cisco CWE-94
6.0
2023-12-12 CVE-2023-20275 Unspecified vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address.
network
low complexity
cisco
4.3
2023-11-01 CVE-2023-20031 Unspecified vulnerability in Cisco Firepower Threat Defense
A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart.
network
high complexity
cisco
5.4
2023-11-01 CVE-2023-20070 Unspecified vulnerability in Cisco Firepower Threat Defense 7.2.0/7.2.0.1
A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart.
network
high complexity
cisco
4.0
2023-11-01 CVE-2023-20071 Unspecified vulnerability in Cisco products
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.
network
low complexity
cisco
5.8
2023-11-01 CVE-2023-20246 Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.
network
low complexity
snort cisco
5.3
2023-11-01 CVE-2023-20247 Unspecified vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and password.
network
low complexity
cisco
4.3
2023-11-01 CVE-2023-20264 Unspecified vulnerability in Cisco products
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user who is authenticating to a remote access VPN session.
network
low complexity
cisco
6.1