First published: Wed Oct 27 2021(Updated: )
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For more information about these vulnerabilities, see the Details section of this advisory. Note: These vulnerabilities have been publicly discussed as NAT Slipstreaming.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance | <9.8.4.40 | |
Cisco Firepower Threat Defense | <6.4.0.12 | |
Cisco Firepower Threat Defense | >=6.5.0<6.6.5 | |
Cisco Firepower Threat Defense | >=6.7.0<6.7.0.2 | |
Cisco Adaptive Security Appliance Software | >=9.12.0<9.12.4.18 | |
Cisco Adaptive Security Appliance Software | >=9.13.0<9.14.2.15 | |
Cisco Adaptive Security Appliance Software | >=9.15.0<9.15.1.15 | |
Cisco Asa 5512-x Firmware | =009.008 | |
Cisco Asa 5512-x Firmware | =009.015 | |
Cisco Asa 5512-x | ||
Cisco Asa 5505 Firmware | =009.008 | |
Cisco Asa 5505 Firmware | =009.015 | |
Cisco Asa 5505 | ||
Cisco Asa 5515-x Firmware | =009.008 | |
Cisco Asa 5515-x Firmware | =009.015 | |
Cisco Asa 5515-x | ||
Cisco Asa 5525-x Firmware | =009.008 | |
Cisco Asa 5525-x Firmware | =009.015 | |
Cisco Asa 5525-x | ||
Cisco Asa 5545-x Firmware | =009.008 | |
Cisco Asa 5545-x Firmware | =009.015 | |
Cisco Asa 5545-x | ||
Cisco Asa 5555-x Firmware | =009.008 | |
Cisco Asa 5555-x Firmware | =009.015 | |
Cisco Asa 5555-x | ||
Cisco Asa 5580 Firmware | =009.008 | |
Cisco Asa 5580 Firmware | =009.015 | |
Cisco Asa 5580 | ||
Cisco Asa 5585-x Firmware | =009.008 | |
Cisco Asa 5585-x Firmware | =009.015 | |
Cisco Asa 5585-x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34791 is a vulnerability in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software.
CVE-2021-34791 has a severity level of 5.3, which is considered medium.
Cisco Adaptive Security Appliance (ASA) Software versions up to 9.8.4.40 and Cisco Firepower Threat Defense (FTD) Software versions up to 6.4.0.12 are affected by CVE-2021-34791.
An unauthenticated, remote attacker can exploit CVE-2021-34791 to bypass the Application Level Gateway (ALG) and open unauthorized connections.
You can find more information about CVE-2021-34791 in the Cisco Security Advisory at https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-natalg-bypass-cpKGqkng.