Vulnerabilities > Cisco > Firepower Threat Defense > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-10-27 CVE-2021-34764 Open Redirect vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack.
network
low complexity
cisco CWE-601
6.1
2021-10-27 CVE-2021-34787 Improper Handling of Exceptional Conditions vulnerability in Cisco products
A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections.
network
low complexity
cisco CWE-755
5.3
2021-10-27 CVE-2021-34790 Improper Input Validation vulnerability in Cisco products
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG.
network
low complexity
cisco CWE-20
5.3
2021-10-27 CVE-2021-34791 Improper Input Validation vulnerability in Cisco products
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG.
network
low complexity
cisco CWE-20
5.3
2021-10-27 CVE-2021-34794 Unspecified vulnerability in Cisco products
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data.
network
low complexity
cisco
5.3
2021-10-27 CVE-2021-40125 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-400
6.5
2021-04-29 CVE-2021-1488 OS Command Injection vulnerability in Cisco products
A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS).
local
low complexity
cisco CWE-78
6.7
2021-04-29 CVE-2021-1495 Improper Handling of Exceptional Conditions vulnerability in multiple products
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP.
network
low complexity
cisco snort CWE-755
5.3
2021-04-29 CVE-2021-1476 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device.
local
low complexity
cisco CWE-78
6.7
2021-04-29 CVE-2021-1256 Files or Directories Accessible to External Parties vulnerability in Cisco Firepower Threat Defense
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques.
local
low complexity
cisco CWE-552
6.0