CVE-2019-15992High· 7.2▾ TwilightA vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.1%
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an affected device. The vulnerability is due to insufficient restrictions on the allowed Lua function calls within the context of user-supplied Lua scripts. A successful exploit could allow the attacker to trigger a heap overflow condition and execute arbitrary code with root privileges on the underlying Linux operating system of an affected device.
adaptive_security_appliance < 9.6.4.36adaptive_security_appliance_software >= 9.7, < 9.8.4.15adaptive_security_appliance_software >= 9.9, < 9.9.2.61adaptive_security_appliance_software >= 9.10, < 9.10.1.32adaptive_security_appliance_software >= 9.12, < 9.12.3adaptive_security_appliance_software >= 9.13, < 9.13.1.4adaptive_security_appliance_software >= 9.14, < 9.14.2.7adaptive_security_appliance_software >= 9.15, < 9.15.1.4secure_firewall_management_center < 6.2.3.16secure_firewall_management_center >= 6.3.0, < 6.3.0.6secure_firewall_management_center >= 6.4.0, < 6.4.0.7secure_firewall_management_center >= 6.5.0, < 6.5.0.2secure_firewall_threat_defenseUpgrade past the affected range:
adaptive_security_appliance 9.6.4.36adaptive_security_appliance_software 9.15.1.4secure_firewall_management_center 6.5.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3562High· 8.6A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affec…
CVE-2020-3283High· 8.6A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote att…
CVE-2019-12673High· 7.5A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an a…
CVE-2026-20352High· 8.6A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper ha…
CVE-2026-20319High· 7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review
CVE-2021-1402High· 8.6A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (D…