CVE-2021-34791: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Application Level Gateway Bypass Vulnerabilities
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For more information about these vulnerabilities, see the Details section of this advisory. Note: These vulnerabilities have been publicly discussed as NAT Slipstreaming.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34791?
CVE-2021-34791 is a vulnerability in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software.
How severe is CVE-2021-34791?
CVE-2021-34791 has a severity level of 5.3, which is considered medium.
Which software versions are affected by CVE-2021-34791?
Cisco Adaptive Security Appliance (ASA) Software versions up to 9.8.4.40 and Cisco Firepower Threat Defense (FTD) Software versions up to 6.4.0.12 are affected by CVE-2021-34791.
How can an attacker exploit CVE-2021-34791?
An unauthenticated, remote attacker can exploit CVE-2021-34791 to bypass the Application Level Gateway (ALG) and open unauthorized connections.
Where can I find more information about CVE-2021-34791?
You can find more information about CVE-2021-34791 in the Cisco Security Advisory at https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-natalg-bypass-cpKGqkng.