---
id: CVE-2019-12627
title: >-
  A vulnerability in the application policy configuration of the Cisco Firepower
  Threat Defense (FTD) Software could allow an unauthenticated, remote attacker
  to gain unauthorized read access to sensitive data
summary: >-
  A vulnerability in the application policy configuration of the Cisco Firepower
  Threat Defense (FTD) Software could allow an unauthenticated, remote attacker
  to gain unauthorized read access to sensitive data. The vulnerability is due
  to …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-284
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - secure_firewall_threat_defense < 6.4.0.4
patched:
  - secure_firewall_threat_defense 6.4.0.4
published: '2019-08-21'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-12627'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-frpwr-td-info
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-frpwr-td-info
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01153
epssPercentile: 0.65562
ingestedAt: '2026-08-11T19:48:26.780Z'
---

## Overview

A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain unauthorized read access to sensitive data.

## Affected

- `secure_firewall_threat_defense < 6.4.0.4`

## Remediation

Upgrade past the affected range:

- `secure_firewall_threat_defense 6.4.0.4`
