CVE-2021-34792: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Resource Exhaustion Denial of Service Vulnerability
A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacker could exploit this vulnerability by opening a significant number of connections on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34792?
The severity of CVE-2021-34792 is classified as high due to its potential to cause a denial of service (DoS) condition.
How do I fix CVE-2021-34792?
To fix CVE-2021-34792, you should upgrade to the patched versions of Cisco ASA or Firepower Threat Defense Software as specified in the advisory.
What are the impacted versions for CVE-2021-34792?
CVE-2021-34792 affects several versions of Cisco Adaptive Security Appliance and Firepower Threat Defense Software, specifically those below specified patch versions.
Is my Cisco device vulnerable to CVE-2021-34792?
To determine if your Cisco device is vulnerable to CVE-2021-34792, check the specific software version against the list of affected versions.
Can CVE-2021-34792 be exploited remotely?
Yes, CVE-2021-34792 can be exploited by an unauthenticated, remote attacker, leading to a DoS condition.