CVE-2020-3578Medium· 5.3▾ SunlitA vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and ac…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked. The vulnerability is due to insufficient validation of URLs when portal access rules are configured. An attacker could exploit this vulnerability by accessing certain URLs on the affected device.
secure_firewall_threat_defense >= 6.4.0, < 6.4.0.10firepower_threat_defense < 6.3.0.6firepower_threat_defense >= 6.5.0, < 6.5.0.5firepower_threat_defense >= 6.6.0, < 6.6.1adaptive_security_appliance_software < 9.6.4.45adaptive_security_appliance_software >= 9.7, < 9.8.4.26adaptive_security_appliance_software >= 9.9, < 9.9.2.80adaptive_security_appliance_software >= 9.10, < 9.10.1.44adaptive_security_appliance_software >= 9.12, < 9.12.4.4adaptive_security_appliance_software >= 9.13, < 9.13.1.13adaptive_security_appliance_software >= 9.14, < 9.14.1.19Upgrade past the affected range:
secure_firewall_threat_defense 6.4.0.10firepower_threat_defense 6.6.1adaptive_security_appliance_software 9.14.1.19Connected by shared product, vendor, weakness, or advisory.
CVE-2025-20224Medium· 5.8A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…
CVE-2026-20012High· 8.6A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Softwar…
CVE-2026-20072Medium· 4.9A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to
CVE-2026-76438Medium· 6.5A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerabili…
CVE-2026-20052Medium· 5.8A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. …
CVE-2026-20007Medium· 5.8A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network …