Cisco
Cisco Adaptive Security Appliance Software: vulnerabilidades y CVE
Cisco Adaptive Security Appliance Software tiene 354 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 8 son críticas y 14 figuran en el catálogo de explotación activa de CISA.
CVE354
Últimos 12 meses26
Críticas8
Explotadas activamente14
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20349 | Alta (8.6) | 1.0% | ⚠ Explotación activa | 11 ago 2026 | This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected… |
| CVE-2025-20333 | Crítica (9.9) | 71% | ⚠ Explotación activa | 25 sept 2025 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute… |
| CVE-2025-20362 | Alta (8.6) | 87% | ⚠ Explotación activa | 25 sept 2025 | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362.… |
| CVE-2014-2120 | Media (6.1) | 23% | ⚠ Explotación activa | 19 mar 2014 | Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug… |
| CVE-2024-20481 | Media (5.8) | 16% | ⚠ Explotación activa | 23 oct 2024 | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a… |
| CVE-2024-20353 | Alta (8.6) | 71% | ⚠ Explotación activa | 24 abr 2024 | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the… |
| CVE-2024-20359 | Media (6) | 19% | ⚠ Explotación activa | 24 abr 2024 | A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)… |
| CVE-2020-3259 | Alta (7.5) | 72% | ⚠ Explotación activa | 6 may 2020 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory… |
| CVE-2023-20269 | Crítica (9.1) | 25% | ⚠ Explotación activa | 6 sept 2023 | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute… |
| CVE-2016-6367 | Alta (7.8) | 23% | ⚠ Explotación activa | 18 ago 2016 | Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA. |
| CVE-2016-6366 | Alta (8.8) | 88% | ⚠ Explotación activa | 18 ago 2016 | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote… |
| CVE-2020-3452 | Alta (7.5) | 100% | ⚠ Explotación activa | 22 jul 2020 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory… |
| CVE-2018-0296 | Alta (7.5) | 100% | ⚠ Explotación activa | 7 jun 2018 | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service… |
| CVE-2020-3580 | Media (6.1) | 86% | ⚠ Explotación activa | 21 oct 2020 | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20349 | Alta (8.6) | 1.0% | ⚠ Explotación activa | 11 ago 2026 | This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected… |
| CVE-2026-20012 | Alta (8.6) | 0.35% | — | 25 mar 2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat… |
| CVE-2026-20025 | Media (6.8) | 0.17% | — | 4 mar 2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a… |
| CVE-2026-20024 | Media (5.7) | 0.20% | — | 4 mar 2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a… |
| CVE-2026-20023 | Media (6.5) | 0.16% | — | 4 mar 2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to… |
| CVE-2026-20022 | Media (6.5) | 0.20% | — | 4 mar 2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in… |
| CVE-2026-20021 | Media (4.3) | 0.21% | — | 4 mar 2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, adjacent attacker to exhaust… |
| CVE-2026-20020 | Media (5.7) | 0.26% | — | 4 mar 2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in… |
| CVE-2026-20016 | Media (6.7) | 0.34% | — | 4 mar 2026 | A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying… |
| CVE-2026-20106 | Media (5.3) | 0.33% | — | 4 mar 2026 | A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an… |
| CVE-2026-20105 | Alta (7.7) | 0.32% | — | 4 mar 2026 | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote… |
| CVE-2026-20103 | Alta (8.6) | 0.36% | — | 4 mar 2026 | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote… |
| CVE-2026-20102 | Media (6.1) | 0.27% | — | 4 mar 2026 | A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a… |
| CVE-2026-20101 | Alta (8.6) | 0.36% | — | 4 mar 2026 | A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly,… |
| CVE-2026-20100 | Alta (7.7) | 0.29% | — | 4 mar 2026 | A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an… |
| CVE-2026-20082 | Alta (8.6) | 0.42% | — | 4 mar 2026 | A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause incoming TCP SYN packets to… |
| CVE-2026-20073 | Media (5.8) | 0.40% | — | 4 mar 2026 | A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be… |
| CVE-2026-20070 | Media (6.1) | 0.27% | — | 4 mar 2026 | This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by persuading a user to follow a link to a malicious website that is designed to… |
| CVE-2026-20069 | Media (4.3) | 0.28% | — | 4 mar 2026 | A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote… |
| CVE-2026-20049 | Alta (7.7) | 0.30% | — | 4 mar 2026 | A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure… |
| CVE-2026-20039 | Alta (8.6) | 0.36% | — | 4 mar 2026 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause… |
| CVE-2026-20015 | Media (5.8) | 0.31% | — | 4 mar 2026 | A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the… |
| CVE-2026-20014 | Alta (7.7) | 0.30% | — | 4 mar 2026 | A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an… |
| CVE-2026-20013 | Media (5.8) | 0.31% | — | 4 mar 2026 | A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also… |
| CVE-2026-20009 | Media (5.3) | 0.40% | — | 4 mar 2026 | A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to… |
| CVE-2026-20008 | Media (6) | 0.14% | — | 4 mar 2026 | A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated,… |
| CVE-2025-20363 | Crítica (9) | 6.9% | — | 25 sept 2025 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR… |
| CVE-2025-20362 | Alta (8.6) | 87% | ⚠ Explotación activa | 25 sept 2025 | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362.… |
| CVE-2025-20333 | Crítica (9.9) | 71% | ⚠ Explotación activa | 25 sept 2025 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute… |
| CVE-2025-20127 | Alta (7.7) | 0.66% | — | 14 ago 2025 | A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.