📦 Adaptive Security Appliance Software

by Cisco

🔍 What is Adaptive Security Appliance Software?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-20333

CRITICAL CVSS 9.9 Sep 25, 2025

This critical vulnerability in Cisco ASA and FTD VPN web servers allows authenticated remote attackers to execute arbitrary code as root. Attackers with valid VPN credentials can exploit improper inpu...

CVE-2025-20363

CRITICAL CVSS 9.0 Sep 25, 2025

This critical vulnerability allows remote attackers to execute arbitrary code with root privileges on affected Cisco devices. Unauthenticated attackers can exploit Cisco ASA/FTD devices, while authent...

CVE-2024-20329

CRITICAL CVSS 9.9 Oct 23, 2024

This critical vulnerability in Cisco ASA Software allows authenticated remote attackers to execute arbitrary operating system commands with root privileges via SSH. Attackers with limited user access ...

CVE-2025-20182

HIGH CVSS 8.6 May 7, 2025

An unauthenticated remote attacker can cause affected Cisco network devices to crash and reload by sending specially crafted IKEv2 protocol messages. This vulnerability affects Cisco ASA, FTD, IOS, an...

CVE-2024-20494

HIGH CVSS 8.6 Oct 23, 2024

A TLS 1.3 handshake vulnerability in Cisco ASA and FTD software allows unauthenticated remote attackers to trigger a device reload, causing denial of service. This affects organizations using affected...

CVE-2024-20408

HIGH CVSS 7.7 Oct 23, 2024

This vulnerability allows authenticated remote attackers with VPN credentials to crash Cisco ASA/FTD devices via crafted HTTPS POST requests, causing denial of service. It affects systems with Dynamic...

CVE-2024-20402

HIGH CVSS 8.6 Oct 23, 2024

A memory management flaw in Cisco ASA and FTD SSL VPN allows unauthenticated remote attackers to trigger device reboots via crafted SSL/TLS packets, causing denial of service. This affects organizatio...

CVE-2024-20268

HIGH CVSS 7.7 Oct 23, 2024

A vulnerability in Cisco ASA and FTD software allows authenticated remote attackers to cause denial of service by sending crafted SNMP packets. The insufficient input validation in SNMP feature enable...

CVE-2023-20086

HIGH CVSS 8.6 Nov 1, 2023

An unauthenticated remote attacker can send crafted ICMPv6 messages to Cisco ASA or FTD devices with IPv6 enabled, causing the device to reload and creating a denial of service condition. This affects...

CVE-2022-20715

HIGH CVSS 8.6 May 3, 2022

This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending crafted requests to the SSL VPN features of Cisco ASA and FTD software, potentially forcing t...

CVE-2022-20737

HIGH CVSS 8.5 May 3, 2022

A heap-based buffer overflow vulnerability in Cisco ASA's Clientless SSL VPN portal allows authenticated remote attackers to cause denial of service or leak sensitive memory contents. Attackers contro...

CVE-2022-20742

HIGH CVSS 7.4 May 3, 2022

This vulnerability allows an unauthenticated remote attacker in a man-in-the-middle position to decrypt, read, modify, and re-encrypt data transmitted across affected IPsec IKEv2 VPN tunnels. It affec...

CVE-2022-20745

HIGH CVSS 8.6 May 3, 2022

An unauthenticated remote attacker can cause a denial of service (DoS) by sending a crafted HTTPS request to Cisco ASA or FTD devices with web services interface for remote access VPN enabled. This af...

CVE-2022-20759

HIGH CVSS 8.8 May 3, 2022

This vulnerability allows authenticated but unprivileged remote attackers to escalate privileges to level 15 (highest administrative level) on Cisco ASA and FTD devices via the web services interface....

CVE-2021-1573

HIGH CVSS 8.6 Jan 11, 2022

An unauthenticated remote attacker can send a malicious HTTPS request to Cisco ASA or FTD devices, causing them to reload and creating a denial of service condition. This affects devices with the web ...

CVE-2021-34792

HIGH CVSS 8.6 Oct 27, 2021

This vulnerability allows unauthenticated remote attackers to cause a denial of service (DoS) by overwhelming Cisco ASA and FTD devices with excessive connections. The improper resource management cau...

CVE-2021-40118

HIGH CVSS 8.6 Oct 27, 2021

An unauthenticated remote attacker can send a malicious HTTPS request to Cisco ASA/FTD devices to trigger a denial of service condition, causing the device to reload. This affects Cisco Adaptive Secur...

CVE-2021-1422

HIGH CVSS 7.7 Jul 16, 2021

A logic error in Cisco ASA and FTD software cryptography modules allows authenticated remote attackers or unauthenticated man-in-the-middle attackers to cause a denial of service by sending malicious ...

CVE-2021-1493

HIGH CVSS 8.5 Apr 29, 2021

This vulnerability allows authenticated remote attackers to trigger a buffer overflow in Cisco ASA and FTD software web services interface by sending malicious HTTP requests. Successful exploitation c...

CVE-2021-1501

HIGH CVSS 8.6 Apr 29, 2021

This vulnerability allows unauthenticated remote attackers to cause a denial of service by sending crafted SIP traffic through affected Cisco ASA and FTD devices. The vulnerability triggers a crash du...

CVE-2024-20526

MEDIUM CVSS 5.3 Oct 23, 2024

An unauthenticated remote attacker can send crafted SSH messages to Cisco ASA devices to exhaust SSH resources, causing a denial of service for new SSH connections. Existing SSH sessions continue work...

CVE-2024-20493

MEDIUM CVSS 5.3 Oct 23, 2024

This vulnerability allows unauthenticated remote attackers to temporarily deny VPN authentication for several minutes by sending crafted packets that exhaust memory resources during the authentication...

CVE-2024-20384

MEDIUM CVSS 5.8 Oct 23, 2024

A logic error in Cisco ASA and FTD software's Network Service Group ACL implementation allows unauthenticated remote attackers to bypass configured access control rules. This affects organizations usi...

CVE-2024-20341

MEDIUM CVSS 6.1 Oct 23, 2024

This vulnerability allows unauthenticated remote attackers to execute cross-site scripting (XSS) attacks against users accessing Cisco ASA/FTD VPN web client services. Attackers can inject malicious s...

CVE-2024-20331

MEDIUM CVSS 6.8 Oct 23, 2024

This vulnerability in Cisco ASA and FTD software allows unauthenticated remote attackers to disrupt VPN authentication sessions by exploiting insufficient entropy. Attackers can terminate legitimate u...

CVE-2024-20355

MEDIUM CVSS 5.0 May 22, 2024

This vulnerability allows authenticated remote attackers to bypass SAML authorization controls in Cisco ASA/FTD VPN services. Attackers can intercept their valid SAML token and reuse it to connect thr...