ASA5585-20-AW3Y
Announced in: Cisco ASA CX Context-Aware Security and Cisco Prime Security Manager
Chassis
· ASA 5500-X series
Is the Cisco ASA CX Context-Aware Security and Cisco Prime Security Manager still supported?
No. Cisco ended support for the Cisco ASA CX Context-Aware Security and Cisco Prime Security Manager on 2020-08-31. No further security fixes will be issued. See Cisco's lifecycle bulletin.
When does the Cisco ASA CX Context-Aware Security and Cisco Prime Security Manager reach end of support?
Cisco support for the Cisco ASA CX Context-Aware Security and Cisco Prime Security Manager ends on 2020-08-31.
What replaces the Cisco ASA CX Context-Aware Security and Cisco Prime Security Manager?
Cisco has not published a successor model for the Cisco ASA CX Context-Aware Security and Cisco Prime Security Manager.
What known-exploited CVEs apply to the ASA5585-20-AW3Y past end of support?
13 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform the Cisco ASA CX Context-Aware Security and Cisco Prime Security Manager runs. These will not be patched on this device because it is past the Cisco security-support date. See the Known Exploited Vulnerabilities table below for the full list.
Known Exploited Vulnerabilities
This device is past Cisco's security-support date. 13 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. Cisco is not issuing patches for this model. Isolate, compensate, or refresh.
| CVE | KEV added | Vulnerability | Flags |
|---|---|---|---|
CVE-2025-20362
|
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | ||
CVE-2025-20333
|
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | ||
CVE-2014-2120
|
Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability | ||
CVE-2024-20481
|
Cisco ASA and FTD Denial-of-Service Vulnerability | ||
CVE-2024-20359
|
Cisco ASA and FTD Privilege Escalation Vulnerability | ||
CVE-2024-20353
|
Cisco ASA and FTD Denial of Service Vulnerability | ||
CVE-2020-3259
|
Cisco ASA and FTD Information Disclosure Vulnerability | Ransomware | |
CVE-2023-20269
|
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability | Ransomware | |
CVE-2016-6366
|
Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability | ||
CVE-2016-6367
|
Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability | ||
CVE-2020-3452
|
Cisco ASA and FTD Read-Only Path Traversal Vulnerability | ||
CVE-2020-3580
|
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability | Ransomware | |
CVE-2018-0296
|
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability |
Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.
Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.
ASA5585-20-AW3Y Lifecycle Overview
The Cisco ASA5585-20-AW3Y (ASA5585-20-AW3Y) is a chassis product in the Cisco ASA 5500-X series. This product has reached end of life as of , meaning Cisco no longer provides technical support, software updates, or hardware replacement for this product. It was last available for purchase on . Organizations still running the ASA5585-20-AW3Y should plan a migration .
Lifecycle Milestones
| Lifecycle notice published | 11y 5mo ago | |
|---|---|---|
| End of sale | 10y 11mo ago | |
| End of failure analysis | 9y 11mo ago | |
| Last date of support | 5y 11mo ago |