---
id: CVE-2019-1694
title: >-
  A vulnerability in the TCP processing engine of Cisco Adaptive Security
  Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software
  could allow an unauthenticated, remote attacker to cause an affected device to
  reload, res…
summary: >-
  A vulnerability in the TCP processing engine of Cisco Adaptive Security
  Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software
  could allow an unauthenticated, remote attacker to cause an affected device to
  reload, res…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: cisco
product: adaptive_security_appliance_software
affected:
  - adaptive_security_appliance_software < 9.4.4.34
  - 'adaptive_security_appliance_software >= 9.5, < 9.6.4.25'
  - 'adaptive_security_appliance_software >= 9.7, < 9.8.4'
  - 'adaptive_security_appliance_software >= 9.9, < 9.9.2.50'
  - 'adaptive_security_appliance_software >= 9.10, < 9.10.1.17'
  - secure_firewall_threat_defense < 6.2.3.12
  - 'secure_firewall_threat_defense >= 6.3.0, < 6.3.0.3'
patched:
  - adaptive_security_appliance_software 9.10.1.17
  - secure_firewall_threat_defense 6.3.0.3
published: '2019-05-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1694'
references:
  - url: 'http://www.securityfocus.com/bid/108160'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-asa-frpwrtd-dos
    label: psirt@cisco.com
  - url: 'http://www.securityfocus.com/bid/108160'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-asa-frpwrtd-dos
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02516
epssPercentile: 0.84132
ingestedAt: '2026-08-11T19:48:26.212Z'
---

## Overview

A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper handling of TCP traffic. An attacker could exploit this vulnerability by sending a specific sequence of packets at a high rate through an affected device. A successful exploit could allow the attacker to temporarily disrupt traffic through the device while it reboots.

## Affected

- `adaptive_security_appliance_software < 9.4.4.34`
- `adaptive_security_appliance_software >= 9.5, < 9.6.4.25`
- `adaptive_security_appliance_software >= 9.7, < 9.8.4`
- `adaptive_security_appliance_software >= 9.9, < 9.9.2.50`
- `adaptive_security_appliance_software >= 9.10, < 9.10.1.17`
- `secure_firewall_threat_defense < 6.2.3.12`
- `secure_firewall_threat_defense >= 6.3.0, < 6.3.0.3`

## Remediation

Upgrade past the affected range:

- `adaptive_security_appliance_software 9.10.1.17`
- `secure_firewall_threat_defense 6.3.0.3`
