Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 21/10/2020 | 11/8/2026 | A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability… | |
| Modificada | Media (6.7) | 0.38% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 21/10/2020 | 11/8/2026 | A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their Cisco FTD instance and execute commands with root privileges in the host namespace. The attacker must have valid credentials on the device.The… | |
| Modificada | Media (6.7) | 0.32% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 21/10/2020 | 11/8/2026 | Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass the secure boot mechanism. The vulnerabilities… | |
| Modificada | Media (6.7) | 0.40% | — | Cisco Firepower Extensible Operating SystemCisco Adaptive Security Appliance SoftwareCisco Firepower Threat Defense | 21/10/2020 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating… | |
| Modificada | Alta (8.6) | 1.9% | — | Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 21/10/2020 | 11/8/2026 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload. The… | |
| Modificada | Alta (8.6) | 2.0% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 21/10/2020 | 11/8/2026 | A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. This memory leak could prevent traffic from being processed… | |
| Modificada | Media (5.5) | 0.27% | — | Cisco Secure Firewall Threat Defense | 21/10/2020 | 11/8/2026 | A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacker could exploit this vulnerability by performing specific steps that make the… | |
| Modificada | Alta (7.5) | 0.97% | — | Cisco Secure Firewall Threat Defense | 21/10/2020 | 11/8/2026 | A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Alta (8.6) | 3.9% | — | Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 21/10/2020 | 11/8/2026 | A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack… | |
| Modificada | Media (5.8) | 2.3% | — | Cisco Secure Firewall Threat DefenseSnort | 21/10/2020 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. The vulnerability is due to incorrect detection of modified HTTP packets used in chunked responses. An attacker could exploit this… | |
| Modificada | Alta (7.2) | 4.1% | — | Cisco Adaptive Security ApplianceCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 23/9/2020 | 11/8/2026 | A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 22/7/2020 | 11/8/2026 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of… | |
| Modificada | Media (5.5) | 0.74% | — | Mcafee Advanced Threat Defense | 22/6/2020 | 17/6/2026 | Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view sensitive files via a carefully crafted HTTP request parameter. | |
| Modificada | Alta (7.4) | 0.43% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 6/5/2020 | 11/8/2026 | A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco IOS | 6/5/2020 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker… | |
| Modificada | Media (4.9) | 0.61% | — | Cisco Secure Firewall Threat DefenseCisco Secure Firewall Management Center | 6/5/2020 | 11/8/2026 | A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Adaptive Security ApplianceCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 6/5/2020 | 11/8/2026 | A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incorrect processing of certain DHCP… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Adaptive Security ApplianceCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 6/5/2020 | 11/8/2026 | A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Adaptive Security ApplianceCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 6/5/2020 | 11/8/2026 | A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 6/5/2020 | 11/8/2026 | A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected device, resulting in a denial of service (DoS) condition. The… | |
| Modificada | Media (5.8) | 1.5% | — | Cisco Secure Firewall Threat Defense | 6/5/2020 | 11/8/2026 | A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3 policy to block traffic for a specific URL. The vulnerability is due to a logic… | |
| Modificada | Alta (8.6) | 2.0% | — | Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+9 | 6/5/2020 | 11/8/2026 | A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The… | |
| Analizada | Alta (7.5) | 72% | ⚠ Explotación activa | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 6/5/2020 | 12/8/2026 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The… | |
| Modificada | Alta (7.5) | 1.9% | — | Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+9 | 6/5/2020 | 11/8/2026 | A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Secure Firewall Threat DefenseCisco ASA 5505 FirmwareCisco ASA 5510 FirmwareCisco ASA 5512-x Firmware+10 | 6/5/2020 | 11/8/2026 | Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The… |