Cisco Adaptive Security Appliance (ASA)
Our sources currently list 337 known vulnerabilities affecting Cisco Adaptive Security Appliance (ASA). 14 are rated critical severity. 13 of 337 are actively exploited according to CISA, the most recent added 25 September 2025.
Last updated: 22 July 2026, 20:07 AEST
Australian advisories
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2020-3452 | High (7.5) | Actively exploited | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, … | |
| CVE-2018-0296 | High (7.5) | Actively exploited | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpected… | |
| CVE-2016-6366 | High (8.8) | Actively exploited | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Modul… | |
| CVE-2025-20362 | Medium (6.5) | Actively exploited | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by… | |
| CVE-2020-3580 | Medium (6.1) | Actively exploited · ransomware | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthen… | |
| CVE-2020-3259 | High (7.5) | Actively exploited · ransomware | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, … | |
| CVE-2024-20353 | High (8.6) | Actively exploited | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthen… | |
| CVE-2025-20333 | Critical (9.9) | Actively exploited | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an aut… | |
| CVE-2016-6367 | High (7.8) | Actively exploited | Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bu… | |
| CVE-2023-20269 | Medium (5.0) | Actively exploited · ransomware | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticate… | |
| CVE-2024-20359 | Medium (6.0) | Actively exploited | A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software a… | |
| CVE-2024-20481 | Medium (5.8) | Actively exploited | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauth… | |
| CVE-2014-2120 | Medium (6.1) | Actively exploited | Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML… | |
| CVE-2020-3187 | Critical (9.1) | Elevated likelihood (97%) | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, … | |
| CVE-2018-0101 | Critical (10.0) | Elevated likelihood (87%) | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause… | |
| CVE-2016-1287 | Critical (9.8) | Elevated likelihood (77%) | Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9… | |
| CVE-2022-20759 | High (8.8) | Elevated likelihood (29%) | A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c… | |
| CVE-2017-3807 | High (8.8) | Elevated likelihood (15%) | A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remot… | |
| CVE-2014-2127 | High (8.5) | Elevated likelihood (11%) | Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 before 8.6(1.13), 9.0 before 9.0(4.1), and 9.1 before 9.1(4.3)… | |
| CVE-2006-0515 | High (7.5) | No exploitation reported | Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows rem… | |
| CVE-2015-6360 | High (7.5) | No exploitation reported | The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686. | |
| CVE-2025-20363 | Critical (9.0) | No exploitation reported | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Ci… | |
| CVE-2006-3906 | Medium (5.0) | No exploitation reported | Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resour… | |
| CVE-2016-6432 | High (8.1) | No exploitation reported | A vulnerability in the Identity Firewall feature of Cisco ASA Software before 9.6(2.1) could allow an unauthenticated, remote attacker to cause a reload of the affected system or t… | |
| CVE-2017-12246 | High (8.6) | No exploitation reported | A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to ca… | |
| CVE-2007-2462 | Critical (10.0) | No exploitation reported | Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 before 7.2(2)8, when using Layer 2 Tunneling Protocol (L2TP) or Remote Management Access, allows re… | |
| CVE-2012-0358 | Critical (9.3) | No exploitation reported | Buffer overflow in the Cisco Port Forwarder ActiveX control in cscopf.ocx, as distributed through the Clientless VPN feature on Cisco Adaptive Security Appliances (ASA) 5500 series… | |
| CVE-2005-3669 | Medium (5.0) | No exploitation reported | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (d… | |
| CVE-2018-0231 | High (8.6) | No exploitation reported | A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an u… | |
| CVE-2017-6608 | High (8.6) | No exploitation reported | A vulnerability in the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause a reload of… | |
| CVE-2018-15454 | High (8.6) | No exploitation reported | A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software cou… | |
| CVE-2007-2461 | High (7.8) | No exploitation reported | The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM m… | |
| CVE-2010-0440 | Medium (4.3) | No exploitation reported | Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2… | |
| CVE-2019-15992 | High (7.2) | No exploitation reported | A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could … | |
| CVE-2012-4661 | Critical (9.0) | No exploitation reported | Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6… | |
| CVE-2018-0240 | High (8.6) | No exploitation reported | Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software … | |
| CVE-2020-3304 | High (8.6) | No exploitation reported | A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker… | |
| CVE-2018-0228 | High (8.6) | No exploitation reported | A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase u… | |
| CVE-2018-0229 | Medium (6.5) | No exploitation reported | A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platf… | |
| CVE-2011-0394 | High (7.8) | No exploitation reported | Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5.1), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), 8.2 before… | |
| CVE-2015-0742 | Medium (5.0) | No exploitation reported | The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115… | |
| CVE-2010-4670 | High (7.8) | No exploitation reported | The Neighbor Discovery (ND) protocol implementation in the IPv6 stack on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier, and Cisco PI… | |
| CVE-2017-6610 | High (7.7) | No exploitation reported | A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of an affected syste… | |
| CVE-2007-2464 | High (7.1) | No exploitation reported | Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allows remote attackers to cause a … | |
| CVE-2019-1687 | High (7.5) | No exploitation reported | A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated… | |
| CVE-2008-2057 | Medium (5.4) | No exploitation reported | The Instant Messenger (IM) inspection engine in Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(4), 8.0.x before 8.0(3)10, and 8.1.x befor… | |
| CVE-2010-4682 | High (7.8) | No exploitation reported | Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (memory consumption) by… | |
| CVE-2007-2463 | High (7.8) | No exploitation reported | Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)17 allows remote attackers to cause a denial of service (devic… | |
| CVE-2017-6609 | High (7.7) | No exploitation reported | A vulnerability in the IPsec code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper… | |
| CVE-2010-4675 | Critical (9.0) | No exploitation reported | Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, … |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
13 of these are being actively exploited right now.
Our Newcastle team can audit your Cisco estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
