Cisco Secure Firewall ASA 9.12
Vulnerabilities, fixed releases, vendor recommendation and support status of the 9.12 branch, from official sources.
Patcharo matches 6 vulnerabilities against Cisco Secure Firewall ASA 9.12: 2 critical, 6 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: none stated. Last source modification: 11 Aug 2026.
Last verified by Patcharo: 30 Sept 2026 at 12:52 UTC
In brief
- Matched CVEs
- 6
- CISA KEV
- 6
- Newest fix stated
- none stated
- Support
- No statement in the catalog
- Recommended maintenance build
- No official recommendation
- Recommended release
- No official recommendation
- CERT-FR
- 3 documents
Support status
From the vendor's published life-cycle policy; support is not a recommendation.
The life-cycle policy Patcharo reads states nothing about this branch.
Vendor recommendation
The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.
Cisco publishes no recommended-release page Patcharo can read. The fixed releases on this site come from the security advisories only; nothing is inferred from version numbers.
Vulnerabilities affecting 9.12
Each record matched to this branch with the fixed release the source states, newest first.
| CVE | Severity | Fixed in | Published |
|---|---|---|---|
| CVE-2025-20362 Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | High8.6CVSS 3.1, HighKEV | No fix stated | |
| CVE-2025-20333 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | Critical9.9CVSS 3.1, CriticalKEV | No fix stated | |
| CVE-2024-20481 Cisco ASA and FTD Denial-of-Service Vulnerability | Medium5.8CVSS 3.1, MediumKEV | No fix stated | |
| CVE-2024-20359 Cisco ASA and FTD Privilege Escalation Vulnerability | Medium6CVSS 3.1, MediumKEV | No fix stated | |
| CVE-2024-20353 Cisco ASA and FTD Denial of Service Vulnerability | High8.6CVSS 3.1, HighKEV | No fix stated | |
| CVE-2023-20269 Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability | Critical9.1CVSS 3.1, CriticalKEVRansomware | No fix stated |
CERT-FR advisories and alerts
Documents of the French national CERT referencing these CVEs, newest first.
- Alert (ALE)CERTFR-2025-ALE-013[MàJ] Multiples vulnérabilités dans Cisco ASA et FTDPublished 25 Sept 2025 · updated 9 Dec 2025 · closed 9 Dec 2025
- Advisory (AVI)CERTFR-2025-AVI-0819Multiples vulnérabilités dans les produits CiscoPublished 25 Sept 2025
- Advisory (AVI)CERTFR-2024-AVI-0919Multiples vulnérabilités dans les produits CiscoPublished 24 Oct 2024
How Patcharo reads this
Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.