First published: Wed Oct 27 2021(Updated: )
A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacker could exploit this vulnerability by opening a significant number of connections on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Firepower Threat Defense (FTD) | >=6.4.0<6.4.0.13 | |
Cisco Firepower Threat Defense (FTD) | >=6.6.0<6.6.5 | |
Cisco Firepower Threat Defense (FTD) | >=6.7.0<6.7.0.3 | |
Cisco Firepower Threat Defense (FTD) | >=7.0.0<7.0.1 | |
Cisco Adaptive Security Appliance Software | >=9.8.0<9.8.4.40 | |
Cisco Adaptive Security Appliance Software | >=9.12.0<9.12.4.29 | |
Cisco Adaptive Security Appliance Software | >=9.14.0<9.14.3.9 | |
Cisco Adaptive Security Appliance Software | >=9.15.0<9.15.1.17 | |
Cisco Adaptive Security Appliance Software | >=9.16.0<9.16.2.3 | |
Cisco ASA 5512-X Firmware | =009.014\(001.150\) | |
Cisco ASA 5512-X Firmware | =099.017\(001.211\) | |
Cisco ASA 5512-X Firmware | =099.017\(001.220\) | |
Cisco ASA 5512-X Firmware | =099.017\(015.050\) | |
Cisco ASA 5512-X firmware | ||
Cisco ASA 5505 firmware | =009.014\(001.150\) | |
Cisco ASA 5505 firmware | =099.017\(001.211\) | |
Cisco ASA 5505 firmware | =099.017\(001.220\) | |
Cisco ASA 5505 firmware | =099.017\(015.050\) | |
Cisco ASA 5505 | ||
Cisco ASA 5515-X Firmware | =009.014\(001.150\) | |
Cisco ASA 5515-X Firmware | =099.017\(001.211\) | |
Cisco ASA 5515-X Firmware | =099.017\(001.220\) | |
Cisco ASA 5515-X Firmware | =099.017\(015.050\) | |
Cisco ASA 5515-X Firmware | ||
Cisco ASA 5525-X Firmware | =009.014\(001.150\) | |
Cisco ASA 5525-X Firmware | =099.017\(001.211\) | |
Cisco ASA 5525-X Firmware | =099.017\(001.220\) | |
Cisco ASA 5525-X Firmware | =099.017\(015.050\) | |
Cisco ASA 5525-X firmware | ||
Cisco ASA 5545-X firmware | =009.014\(001.150\) | |
Cisco ASA 5545-X firmware | =099.017\(001.211\) | |
Cisco ASA 5545-X firmware | =099.017\(001.220\) | |
Cisco ASA 5545-X firmware | =099.017\(015.050\) | |
Cisco ASA 5545-X firmware | ||
Cisco ASA 5555-X Firmware | =009.014\(001.150\) | |
Cisco ASA 5555-X Firmware | =099.017\(001.211\) | |
Cisco ASA 5555-X Firmware | =099.017\(001.220\) | |
Cisco ASA 5555-X Firmware | =099.017\(015.050\) | |
Cisco ASA 5555-x firmware | ||
Cisco ASA 5580 Firmware | =009.014\(001.150\) | |
Cisco ASA 5580 Firmware | =099.017\(001.211\) | |
Cisco ASA 5580 Firmware | =099.017\(001.220\) | |
Cisco ASA 5580 Firmware | =099.017\(015.050\) | |
Cisco ASA 5580 Firmware | ||
Cisco ASA 5585-X | =009.014\(001.150\) | |
Cisco ASA 5585-X | =099.017\(001.211\) | |
Cisco ASA 5585-X | =099.017\(001.220\) | |
Cisco ASA 5585-X | =099.017\(015.050\) | |
Cisco ASA 5585-X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-34792 is classified as high due to its potential to cause a denial of service (DoS) condition.
To fix CVE-2021-34792, you should upgrade to the patched versions of Cisco ASA or Firepower Threat Defense Software as specified in the advisory.
CVE-2021-34792 affects several versions of Cisco Adaptive Security Appliance and Firepower Threat Defense Software, specifically those below specified patch versions.
To determine if your Cisco device is vulnerable to CVE-2021-34792, check the specific software version against the list of affected versions.
Yes, CVE-2021-34792 can be exploited by an unauthenticated, remote attacker, leading to a DoS condition.