---
id: CVE-2019-1695
title: >-
  A vulnerability in the detection engine of Cisco Adaptive Security Appliance
  (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow
  an unauthenticated, adjacent attacker to send data directly to the kernel of
  an aff…
summary: >-
  A vulnerability in the detection engine of Cisco Adaptive Security Appliance
  (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow
  an unauthenticated, adjacent attacker to send data directly to the kernel of
  an aff…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-284
vendor: cisco
product: adaptive_security_appliance_software
affected:
  - adaptive_security_appliance_software < 9.8.4
  - 'secure_firewall_threat_defense >= 6.2.1, < 6.2.3.12'
  - 'secure_firewall_threat_defense >= 6.3.0, < 6.3.0.3'
  - 'adaptive_security_appliance_software >= 9.9, < 9.9.2.50'
  - 'adaptive_security_appliance_software >= 9.10, < 9.10.1.17'
patched:
  - adaptive_security_appliance_software 9.10.1.17
  - secure_firewall_threat_defense 6.3.0.3
published: '2019-05-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1695'
references:
  - url: 'http://www.securityfocus.com/bid/108173'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-asa-ftd-bypass
    label: psirt@cisco.com
  - url: 'http://www.securityfocus.com/bid/108173'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-asa-ftd-bypass
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00706
epssPercentile: 0.51944
ingestedAt: '2026-08-11T19:48:26.414Z'
---

## Overview

A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected device. An attacker could exploit this vulnerability by sending crafted packets to the management interface of an affected device. A successful exploit could allow the attacker to bypass the Layer 2 (L2) filters and send data directly to the kernel of the affected device. A malicious frame successfully delivered would make the target device generate a specific syslog entry.

## Affected

- `adaptive_security_appliance_software < 9.8.4`
- `secure_firewall_threat_defense >= 6.2.1, < 6.2.3.12`
- `secure_firewall_threat_defense >= 6.3.0, < 6.3.0.3`
- `adaptive_security_appliance_software >= 9.9, < 9.9.2.50`
- `adaptive_security_appliance_software >= 9.10, < 9.10.1.17`

## Remediation

Upgrade past the affected range:

- `adaptive_security_appliance_software 9.10.1.17`
- `secure_firewall_threat_defense 6.3.0.3`
