V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2021-34787
CVE
Medium

A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco…

CVSS
5.3
Medium
EPSS
0.01
p78
Published
2021-01-01
Updated
2021-01-01
Description

A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. An attacker could exploit this vulnerability by sending a specially crafted network request to an affected device. A successful exploit could allow the attacker to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts.

Tags · CWE
Pre-auth
CWE-183
CAPEC-3
CAPEC-43
CAPEC-71
CAPEC-120
Affected products
Adaptive_security_appliance < 9.8.4.40Firepower_threat_defense < 6.4.0.13Firepower_threat_defense 6.5.0–6.6.5Firepower_threat_defense 6.7.0–6.7.0.3Firepower_threat_defense 7.0.0–7.0.1Adaptive_security_appliance_software 9.9.0–9.12.4.25Adaptive_security_appliance_software 9.13.0–9.14.3.1Adaptive_security_appliance_software 9.15.0–9.15.1.17Adaptive_security_appliance_software 9.16.0–9.16.1.28
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.012 · p78
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
adaptive_security_appliance*Tracked
adaptive_security_appliance_software*Tracked
asa_5505_firmware*Tracked
asa_5512-x_firmware*Tracked
asa_5515-x_firmware*Tracked
asa_5525-x_firmware*Tracked
asa_5545-x_firmware*Tracked
asa_5555-x_firmware*Tracked
asa_5580_firmware*Tracked
asa_5585-x_firmware*Tracked
firepower_threat_defense*Tracked
Source databases
CVE
Related vulnerabilities