CVE-2021-34753
MEDIUMCisco Firepower Threat Defense Software < 6.4.0.13 - Unauthenticated Access Control Bypass via ENIP Packet Inspection
Title source: llmDescription
A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. This vulnerability is due to incomplete processing during deep packet inspection for ENIP packets. An attacker could exploit this vulnerability by sending a crafted ENIP packet to the targeted interface. A successful exploit could allow the attacker to bypass configured access control and intrusion policies that should trigger and drop for the ENIP packet.
References (1)
Core 1
Core References
Scores
CVSS v3
5.8
EPSS
0.0008
EPSS Percentile
23.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (2)
cisco/firepower_threat_defense_software
7.0.0
cisco/firepower_threat_defense_software
< 6.4.0.13
Published
Nov 15, 2024
Tracked Since
Feb 18, 2026