First published: Wed Oct 27 2021(Updated: )
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit this vulnerability by sending a malicious HTTPS request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | <9.8.4.40 | |
Cisco Secure Firewall Threat Defense | <6.4.0.13 | |
Cisco Secure Firewall Threat Defense | >=6.5.0<6.6.5 | |
Cisco Secure Firewall Threat Defense | >=6.7.0<6.7.0.3 | |
Cisco Secure Firewall Threat Defense | >=7.0.0<7.0.1 | |
Cisco Adaptive Security Appliance Software | >=9.9.0<9.12.4.29 | |
Cisco Adaptive Security Appliance Software | >=9.13.0<9.14.3.9 | |
Cisco Adaptive Security Appliance Software | >=9.15.0<9.15.1.17 | |
Cisco Adaptive Security Appliance Software | >=9.16.0<9.16.2.3 | |
Cisco ASA 5512-X firmware | =009.012\(004.024\) | |
Cisco ASA 5512-X firmware | =009.015\(001\) | |
Cisco ASA 5512-X firmware | =009.015\(001.015\) | |
Cisco ASA 5512-X firmware | =009.015\(001.016\) | |
Cisco ASA 5512-X firmware | =009.016\(001\) | |
Cisco ASA 5512-X Firmware | ||
Cisco ASA 5505 Firmware | =009.012\(004.024\) | |
Cisco ASA 5505 Firmware | =009.015\(001\) | |
Cisco ASA 5505 Firmware | =009.015\(001.015\) | |
Cisco ASA 5505 Firmware | =009.015\(001.016\) | |
Cisco ASA 5505 Firmware | =009.016\(001\) | |
Cisco ASA 5505 Firmware | ||
Cisco ASA 5515-X Firmware | =009.012\(004.024\) | |
Cisco ASA 5515-X Firmware | =009.015\(001\) | |
Cisco ASA 5515-X Firmware | =009.015\(001.015\) | |
Cisco ASA 5515-X Firmware | =009.015\(001.016\) | |
Cisco ASA 5515-X Firmware | =009.016\(001\) | |
Cisco ASA 5515-X Firmware | ||
Cisco ASA 5525-X Firmware | =009.012\(004.024\) | |
Cisco ASA 5525-X Firmware | =009.015\(001\) | |
Cisco ASA 5525-X Firmware | =009.015\(001.015\) | |
Cisco ASA 5525-X Firmware | =009.015\(001.016\) | |
Cisco ASA 5525-X Firmware | =009.016\(001\) | |
Cisco ASA Software | ||
Cisco ASA 5545-X firmware | =009.012\(004.024\) | |
Cisco ASA 5545-X firmware | =009.015\(001\) | |
Cisco ASA 5545-X firmware | =009.015\(001.015\) | |
Cisco ASA 5545-X firmware | =009.015\(001.016\) | |
Cisco ASA 5545-X firmware | =009.016\(001\) | |
Cisco ASA Software | ||
Cisco ASA 5555-X | =009.012\(004.024\) | |
Cisco ASA 5555-X | =009.015\(001\) | |
Cisco ASA 5555-X | =009.015\(001.015\) | |
Cisco ASA 5555-X | =009.015\(001.016\) | |
Cisco ASA 5555-X | =009.016\(001\) | |
Cisco ASA 5555-X Firmware | ||
Cisco ASA 5580 Firmware | =009.012\(004.024\) | |
Cisco ASA 5580 Firmware | =009.015\(001\) | |
Cisco ASA 5580 Firmware | =009.015\(001.015\) | |
Cisco ASA 5580 Firmware | =009.015\(001.016\) | |
Cisco ASA 5580 Firmware | =009.016\(001\) | |
Cisco ASA 5580 Firmware | ||
Cisco ASA 5585-X | =009.012\(004.024\) | |
Cisco ASA 5585-X | =009.015\(001\) | |
Cisco ASA 5585-X | =009.015\(001.015\) | |
Cisco ASA 5585-X | =009.015\(001.016\) | |
Cisco ASA 5585-X | =009.016\(001\) | |
Cisco ASA 5585-X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40118 has been assigned a CVSS score indicating a high severity risk due to the potential for denial of service.
CVE-2021-40118 affects users running vulnerable versions of Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software.
To fix CVE-2021-40118, users should update to the latest patched versions of the affected Cisco software.
CVE-2021-40118 is classified as a denial of service (DoS) vulnerability that can be exploited by unauthenticated remote attackers.
Yes, CVE-2021-40118 can be exploited remotely by unauthenticated attackers to cause a denial of service condition.