---
id: CVE-2019-12673
title: >-
  A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA)
  Software and Cisco Firepower Threat Defense (FTD) Software could allow an
  unauthenticated, remote attacker to cause a denial of service (DoS) condition
  on an a…
summary: >-
  A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA)
  Software and Cisco Firepower Threat Defense (FTD) Software could allow an
  unauthenticated, remote attacker to cause a denial of service (DoS) condition
  on an a…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-119
  - CWE-20
vendor: cisco
product: adaptive_security_appliance
affected:
  - adaptive_security_appliance < 9.6.4.34
  - 'adaptive_security_appliance_software >= 9.7, < 9.8.4.10'
  - 'adaptive_security_appliance_software >= 9.9, < 9.9.2.56'
  - 'adaptive_security_appliance_software >= 9.10, < 9.10.1.30'
  - 'adaptive_security_appliance_software >= 9.12, < 9.12.2.5'
  - secure_firewall_threat_defense < 6.3.0.5
  - 'secure_firewall_threat_defense >= 6.4.0, < 6.4.0.4'
patched:
  - adaptive_security_appliance 9.6.4.34
  - adaptive_security_appliance_software 9.12.2.5
  - secure_firewall_threat_defense 6.4.0.4
published: '2019-10-02'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-12673'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-dos
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-dos
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01772
epssPercentile: 0.77169
ingestedAt: '2026-08-11T19:48:26.813Z'
---

## Overview

A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of FTP data. An attacker could exploit this vulnerability by sending malicious FTP traffic through an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.

## Affected

- `adaptive_security_appliance < 9.6.4.34`
- `adaptive_security_appliance_software >= 9.7, < 9.8.4.10`
- `adaptive_security_appliance_software >= 9.9, < 9.9.2.56`
- `adaptive_security_appliance_software >= 9.10, < 9.10.1.30`
- `adaptive_security_appliance_software >= 9.12, < 9.12.2.5`
- `secure_firewall_threat_defense < 6.3.0.5`
- `secure_firewall_threat_defense >= 6.4.0, < 6.4.0.4`

## Remediation

Upgrade past the affected range:

- `adaptive_security_appliance 9.6.4.34`
- `adaptive_security_appliance_software 9.12.2.5`
- `secure_firewall_threat_defense 6.4.0.4`
