CVE-2021-34787

MEDIUMCVSS 5.3/10EPSS 1.00%

Last modified

CVE-2021-34787 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. EPSS estimates a 1.00% chance of exploitation in the next 30 days.

Description

A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. An attacker could exploit this vulnerability by sending a specially crafted network request to an affected device. A successful exploit could allow the attacker to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS Probability
1.00%

58.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoAdaptive Security Appliance< 9.8.4.40
CiscoFirepower Threat Defense< 6.4.0.13
CiscoFirepower Threat Defense>= 6.5.0, < 6.6.5
CiscoFirepower Threat Defense>= 6.7.0, < 6.7.0.3
CiscoFirepower Threat Defense>= 7.0.0, < 7.0.1
CiscoAdaptive Security Appliance Software>= 9.9.0, < 9.12.4.25
CiscoAdaptive Security Appliance Software>= 9.13.0, < 9.14.3.1
CiscoAdaptive Security Appliance Software>= 9.15.0, < 9.15.1.17
CiscoAdaptive Security Appliance Software>= 9.16.0, < 9.16.1.28
CiscoAsa 5512-X Firmware009.009
CiscoAsa 5512-X Firmware009.012
CiscoAsa 5505 Firmware009.009
CiscoAsa 5505 Firmware009.012
CiscoAsa 5515-X Firmware009.009
CiscoAsa 5515-X Firmware009.012
CiscoAsa 5525-X Firmware009.009
CiscoAsa 5525-X Firmware009.012
CiscoAsa 5545-X Firmware009.009
CiscoAsa 5545-X Firmware009.012
CiscoAsa 5555-X Firmware009.009
CiscoAsa 5555-X Firmware009.012
CiscoAsa 5580 Firmware009.009
CiscoAsa 5580 Firmware009.012
CiscoAsa 5585-X Firmware009.009
CiscoAsa 5585-X Firmware009.012

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-34787?
A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. An attacker could exploit this vulnerability by sending a specially crafted network request to an affected device. A successful exploit could allow the attacker to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts.
How severe is CVE-2021-34787?
CVE-2021-34787 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 1.00% probability of exploitation in the next 30 days.
How do I fix CVE-2021-34787?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-34787?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST