VYPR

Adaptive Security Appliance (ASA) Software

by Cisco Systems, Inc.

CVEs (258)

  • CVE-2019-1715MedMay 3, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to…

  • CVE-2019-1705MedMay 3, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with…

  • CVE-2016-1445MedJul 12, 2016
    risk 0.35cvss 5.3epss 0.01

    Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.

  • CVE-2016-1295MedJan 16, 2016
    risk 0.35cvss 5.3epss 0.02

    Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.

  • CVE-2024-20526MedOct 23, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server of an affected device. This vulnerability is due to a logic error when an SSH…

  • CVE-2024-20493MedOct 23, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user…

  • CVE-2024-20355MedMay 22, 2024
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to successfully establish a…

  • CVE-2023-20247MedNov 1, 2023
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect…

  • CVE-2023-20256MedNov 1, 2023
    risk 0.33cvss 5.0epss 0.01

    Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that…

  • CVE-2019-12693MedOct 2, 2019
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the use of an incorrect data type for a length variable.…

  • CVE-2021-34791MedOct 27, 2021
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and…

  • CVE-2021-34790MedOct 27, 2021
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and…

  • CVE-2020-3561MedOct 21, 2020
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the affected system. The…

  • CVE-2019-1701MedMay 3, 2019
    risk 0.31cvss 4.8epss 0.01

    Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal…

  • CVE-2022-20713MedAug 10, 2022
    risk 0.28cvss 4.3epss 0.02

    A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device.…

  • CVE-2015-6423MedJan 15, 2016
    risk 0.28cvss 4.3epss 0.01

    The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remote authenticated users to bypass an intended DCERPC-only ACL by sending arbitrary network traffic, aka Bug ID CSCuu67782.

  • CVE-2023-20275MedDec 12, 2023
    risk 0.27cvss 4.1epss 0.00

    A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is…

  • CVE-2018-15398MedOct 5, 2018
    risk 0.26cvss 4.0epss 0.02

    A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an…

  • CVE-2014-2127Apr 10, 2014
    risk 0.04cvss —epss 0.11

    Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 before 8.6(1.13), 9.0 before 9.0(4.1), and 9.1 before 9.1(4.3) does not properly process management-session information during privilege validation for SSL VPN…

  • CVE-2009-1201Jun 25, 2009
    risk 0.04cvss —epss 0.09

    Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by…

Page 8 of 13