A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. An attacker could exploit this vulnerability by sending a specially crafted network request to an affected device. A successful exploit could allow the attacker to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Adaptive Security Appliance
Subscribe
Adaptive Security Appliance Software
Subscribe
Asa 5505
Subscribe
Asa 5505 Firmware
Subscribe
Asa 5512-x
Subscribe
Asa 5512-x Firmware
Subscribe
Asa 5515-x
Subscribe
Asa 5515-x Firmware
Subscribe
Asa 5525-x
Subscribe
Asa 5525-x Firmware
Subscribe
Asa 5545-x
Subscribe
Asa 5545-x Firmware
Subscribe
Asa 5555-x
Subscribe
Asa 5555-x Firmware
Subscribe
Asa 5580
Subscribe
Asa 5580 Firmware
Subscribe
Asa 5585-x
Subscribe
Asa 5585-x Firmware
Subscribe
Firepower Threat Defense
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21437 | A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. An attacker could exploit this vulnerability by sending a specially crafted network request to an affected device. A successful exploit could allow the attacker to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 07 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-07T21:45:57.012Z
Reserved: 2021-06-15T00:00:00
Link: CVE-2021-34787
Updated: 2024-08-04T00:19:48.219Z
Status : Modified
Published: 2021-10-27T19:15:08.347
Modified: 2024-11-21T06:11:12.123
Link: CVE-2021-34787
No data.
OpenCVE Enrichment
No data.
EUVD