Known vulnerabilities in Cisco Firepower 9300 Security Appliance
Vendor:
Cisco Systems, Inc
Software:
Cisco Firepower 9300 Security Appliance
Software CPE:
cpe:2.3:h:cisco_systems:cisco_firepower_9300_security_appliance:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
17
Public exploits:
3
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.3.1.173
2.4.1.266
2.6.1.187
2.7.1.106
2.8.1.105
2.4(200.10)
2.7(1.122)
1.1(4.179)
2.0(1.150)
2.1(1.86)
2.2(1.70)
2.2(2.14)
92.3(1.2047)
2.2(2.120)
2.2(2.121)
2.3(1.146)
2.3(1.152)
2.4(1.249)
2.6(1.102)
6.2(3.14)
9.8(4.7)
9.9(2.52)
9.9(2.56)
82.7(1.1077)
82.7(100.279)
1.1(4.168)
2.0(1.140)
2.1(1.47)
2.1(1.1764)
2.2(1.101)
2.0(1.68)
2.0.1
1.1.4
1.1.3
Vulnerabilities (17)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU86915 - Memory corruption CVE-2024-20294 |
CWE-119 | Medium | - | 29.02.2024 |
SB2024022925 SB2024061419 SB2024061703 and 1 more |
||
| #VU72513 - Key Management Errors CVE-2023-20016 |
CWE-320 | Low | - | 23.02.2023 |
SB2023022317 |
||
| #VU72511 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-20015 |
CWE-78 | Low | - | 23.02.2023 |
SB2023022311 |
||
| #VU66752 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-20865 |
CWE-78 | Low | - | 24.08.2022 |
SB2022082443 |
||
| #VU56875 - Improper input validation CVE-2021-34714 |
CWE-20 | Medium | - | 24.09.2021 |
SB2021092427 |
||
| #VU52740 - Command injection CVE-2021-1448 |
CWE-77 | Low | - | 29.04.2021 |
SB2021042908 |
||
| #VU52739 - Resource exhaustion CVE-2021-1489 |
CWE-400 | Low | - | 29.04.2021 |
SB2021042907 |
||
| #VU46250 - Memory corruption CVE-2020-3545 |
CWE-119 | Low | - | 03.09.2020 |
SB2020090309 |
||
| #VU46104 - NULL Pointer Dereference CVE-2020-3517 |
CWE-476 | Medium | 1.1.4.179, 2.0.1.150, 2.1.1.86, 2.2.1.70, 2.2.2.14, 92.3.1.2047 | 27.08.2020 |
SB2020082717 |
||
| #VU49026 - Integer overflow CVE-2020-3120 |
CWE-190 | Low | 2.3.1.173, 2.4.1.266, 2.6.1.187, 2.7.1.106, 2.8.1.105 | 05.02.2020 |
SB2020020539 |
||
| #VU21629 - Resource exhaustion CVE-2019-12700 |
CWE-400 | Medium | 2.2.2.120, 2.2.2.121, 2.3.1.146, 2.3.1.152, 2.4.1.249, 2.6.1.102, 6.2.3.14, 9.8.4.7, 9.9.2.52, 9.9.2.56, 82.7.1.1077, 82.7.100.279 | 08.10.2019 |
SB2019100810 |
||
| #VU15667 - Improper input validation CVE-2018-15454 |
CWE-20 | High | - | 01.11.2018 |
SB2018110101 |
||
| #VU13409 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2018-0300 |
CWE-22 | High | 1.1.4.168, 2.0.1.140, 2.1.1.47, 2.1.1.1764, 2.2.1.101 | 20.06.2018 |
SB2018062109 |
||
| #VU13246 - Relative Path Traversal CVE-2018-0296 |
CWE-23 | Medium | - | 06.06.2018 |
SB2018060810 SB2018070402 |
||
| #VU10328 - Double Free CVE-2018-0101 |
CWE-415 | Critical | - | 29.01.2018 |
SB2018012914 |
||
| #VU9093 - Command injection CVE-2017-12277 |
CWE-77 | Low | - | 02.11.2017 |
SB2017110213 |
||
| #VU9092 - Improper input validation CVE-2017-12243 |
CWE-20 | Low | - | 02.11.2017 |
SB2017110212 |