CVE-2021-34783

HIGH

Cisco ASA/Firepower Threat Defense - Unauthenticated DoS via Crafted SSL/TLS Message

Title source: llm
STIX 2.1

Description

A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient validation of SSL/TLS messages when the device performs software-based SSL/TLS decryption. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: Datagram TLS (DTLS) messages cannot be used to exploit this vulnerability.

References (1)

Core 1

Scores

CVSS v3 8.6
EPSS 0.0077
EPSS Percentile 73.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-119 CWE-20
Status published
Products (18)
cisco/adaptive_security_appliance_software 9.8.0 - 9.8.4.40
cisco/asa_5505_firmware 009.016\(001\)
cisco/asa_5505_firmware 009.016\(001.025\)
cisco/asa_5512-x_firmware 009.016\(001\)
cisco/asa_5512-x_firmware 009.016\(001.025\)
cisco/asa_5515-x_firmware 009.016\(001\)
cisco/asa_5515-x_firmware 009.016\(001.025\)
cisco/asa_5525-x_firmware 009.016\(001\)
cisco/asa_5525-x_firmware 009.016\(001.025\)
cisco/asa_5545-x_firmware 009.016\(001\)
... and 8 more
Published Oct 27, 2021
Tracked Since Feb 18, 2026