Vulnerabilities > Cisco > Firepower Threat Defense > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-05-06 CVE-2020-3255 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-400
5.0
2020-05-06 CVE-2020-3189 Memory Leak vulnerability in Cisco products
A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behaviors or device crashes.
network
low complexity
cisco CWE-401
5.0
2020-05-06 CVE-2020-3188 Insufficient Session Expiration vulnerability in Cisco products
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition.
network
low complexity
cisco CWE-613
5.0
2020-05-06 CVE-2020-3186 Unspecified vulnerability in Cisco products
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system.
network
low complexity
cisco
5.0
2020-02-26 CVE-2020-3166 Improper Input Validation vulnerability in Cisco products
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS).
local
low complexity
cisco CWE-20
6.7
2019-11-05 CVE-2019-1982 Incorrect Default Permissions vulnerability in Cisco products
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections.
network
low complexity
cisco CWE-276
5.0
2019-11-05 CVE-2019-1981 Improper Input Validation vulnerability in Cisco products
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections.
network
low complexity
cisco CWE-20
5.0
2019-11-05 CVE-2019-1980 Improper Authentication vulnerability in Cisco products
A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections.
network
low complexity
cisco CWE-287
5.0
2019-11-05 CVE-2019-1978 Improper Input Validation vulnerability in Cisco products
A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections.
network
low complexity
cisco CWE-20
5.0
2019-10-02 CVE-2019-12700 Unspecified vulnerability in Cisco products
A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco
6.5