Mon, Jan 29 · 08:29 PM CSTCVE-2018-0101
10.0/10 · Must read/watchNVDvuln
Summary
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when
CVECVE-2018-0101
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 29 · 08:29 PM CST
ModifiedTue, Aug 11 · 07:33 PM CDT
Thu, Mar 12 · 04:15 PM CDTCVE-2020-0796
10.0/10 · Must read/watchNVDvuln
Summary
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVECVE-2020-0796
SeverityCRITICAL
TypeUPDATED
PublishedThu, Mar 12 · 04:15 PM CDT
ModifiedWed, Aug 12 · 05:17 AM CDT
Wed, May 22 · 05:29 PM CDTCVE-2019-11634
9.8/10 · Must read/watchNVDvuln
Summary
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CVECVE-2019-11634
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 22 · 05:29 PM CDT
ModifiedWed, Aug 12 · 05:17 AM CDT
Fri, Dec 27 · 02:15 PM CSTCVE-2019-19781
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVECVE-2019-19781
SeverityCRITICAL
TypeUPDATED
PublishedFri, Dec 27 · 02:15 PM CST
ModifiedWed, Aug 12 · 05:17 AM CDT
Fri, Apr 26 · 07:29 PM CDTCVE-2019-2725
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successf
CVECVE-2019-2725
SeverityCRITICAL
TypeUPDATED
PublishedFri, Apr 26 · 07:29 PM CDT
ModifiedWed, Aug 12 · 05:17 AM CDT
Fri, Jul 24 · 11:15 PM CDTCVE-2020-12812
9.8/10 · Must read/watchNVDvuln
Summary
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.
CVECVE-2020-12812
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 24 · 11:15 PM CDT
ModifiedWed, Aug 12 · 05:17 AM CDT
Tue, Oct 20 · 05:15 PM CDTCVE-2020-3992
9.8/10 · Must read/watchNVDvuln
Summary
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP serv
CVECVE-2020-3992
SeverityCRITICAL
TypeUPDATED
PublishedTue, Oct 20 · 05:15 PM CDT
ModifiedWed, Aug 12 · 05:17 AM CDT
Wed, May 06 · 05:15 PM CDTCVE-2020-3187
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulner
CVECVE-2020-3187
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 06 · 05:15 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Wed, Oct 02 · 07:15 PM CDTCVE-2019-12675
8.8/10 · Worth your timeNVDvuln
Summary
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections o
CVECVE-2019-12675
SeverityHIGH
TypeUPDATED
PublishedWed, Oct 02 · 07:15 PM CDT
ModifiedTue, Aug 11 · 07:37 PM CDT
Thu, Apr 19 · 08:29 PM CDTCVE-2018-0228
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incorrect handlin
CVECVE-2018-0228
SeverityHIGH
TypeUPDATED
PublishedThu, Apr 19 · 08:29 PM CDT
ModifiedTue, Aug 11 · 07:37 PM CDT
Thu, Apr 19 · 08:29 PM CDTCVE-2018-0230
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. T
CVECVE-2018-0230
SeverityHIGH
TypeUPDATED
PublishedThu, Apr 19 · 08:29 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Thu, Apr 19 · 08:29 PM CDTCVE-2018-0231
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition. The vulnerabil
CVECVE-2018-0231
SeverityHIGH
TypeUPDATED
PublishedThu, Apr 19 · 08:29 PM CDT
ModifiedTue, Aug 11 · 07:37 PM CDT
Thu, Apr 19 · 08:29 PM CDTCVE-2018-0240
8.6/10 · Worth your timeNVDvuln
Summary
Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
CVECVE-2018-0240
SeverityHIGH
TypeUPDATED
PublishedThu, Apr 19 · 08:29 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Fri, May 03 · 03:29 PM CDTCVE-2018-15388
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for existing W
CVECVE-2018-15388
SeverityHIGH
TypeUPDATED
PublishedFri, May 03 · 03:29 PM CDT
ModifiedTue, Aug 11 · 07:37 PM CDT
Thu, Nov 01 · 12:29 PM CDTCVE-2018-15454
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (Do
CVECVE-2018-15454
SeverityHIGH
TypeUPDATED
PublishedThu, Nov 01 · 12:29 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Fri, May 03 · 03:29 PM CDTCVE-2018-15462
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an increase in CPU and memory usage, resulting in a denial of service (DoS) condition. The vulnerability
CVECVE-2018-15462
SeverityHIGH
TypeUPDATED
PublishedFri, May 03 · 03:29 PM CDT
ModifiedTue, Aug 11 · 07:37 PM CDT
Wed, Oct 02 · 07:15 PM CDTCVE-2019-15256
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vu
CVECVE-2019-15256
SeverityHIGH
TypeUPDATED
PublishedWed, Oct 02 · 07:15 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Thu, Jan 24 · 04:29 PM CSTCVE-2019-1669
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition. The vulnerability exists because the affected software improperly manages sy
CVECVE-2019-1669
SeverityHIGH
TypeUPDATED
PublishedThu, Jan 24 · 04:29 PM CST
ModifiedTue, Aug 11 · 07:33 PM CDT
Fri, May 03 · 03:29 PM CDTCVE-2019-1694
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the impr
CVECVE-2019-1694
SeverityHIGH
TypeUPDATED
PublishedFri, May 03 · 03:29 PM CDT
ModifiedTue, Aug 11 · 07:37 PM CDT
Fri, May 03 · 04:29 PM CDTCVE-2019-1703
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability
CVECVE-2019-1703
SeverityHIGH
TypeUPDATED
PublishedFri, May 03 · 04:29 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Fri, May 03 · 04:29 PM CDTCVE-2019-1708
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device th
CVECVE-2019-1708
SeverityHIGH
TypeUPDATED
PublishedFri, May 03 · 04:29 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Fri, May 03 · 05:29 PM CDTCVE-2019-1714
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attack
CVECVE-2019-1714
SeverityHIGH
TypeUPDATED
PublishedFri, May 03 · 05:29 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Wed, May 06 · 05:15 PM CDTCVE-2020-3189
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behaviors or device crashes. The vulnerability is due to the system
CVECVE-2020-3189
SeverityHIGH
TypeUPDATED
PublishedWed, May 06 · 05:15 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Wed, May 06 · 05:15 PM CDTCVE-2020-3191
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to im
CVECVE-2020-3191
SeverityHIGH
TypeUPDATED
PublishedWed, May 06 · 05:15 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT
Wed, May 06 · 05:15 PM CDTCVE-2020-3196
8.6/10 · Worth your timeNVDvuln
Summary
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of servic
CVECVE-2020-3196
SeverityHIGH
TypeUPDATED
PublishedWed, May 06 · 05:15 PM CDT
ModifiedTue, Aug 11 · 07:33 PM CDT