CVE-2021-34787 Details
Description
A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. An attacker could exploit this vulnerability by sending a specially crafted network request to an affected device. A successful exploit could allow the attacker to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 7, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-755 | Improper Handling of Exceptional Conditions | [email protected] |
| CWE-183 | Permissive List of Allowed Inputs | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco adaptive security appliance | < 9.8.4.40 |
CPE
Remediation
| |
| cisco secure firewall threat defense | < 6.4.0.13 >= 6.5.0, < 6.6.5 >= 6.7.0, < 6.7.0.3 >= 7.0.0, < 7.0.1 |
CPE
Remediation
| |
| cisco adaptive security appliance software | >= 9.9.0, < 9.12.4.25 >= 9.13.0, < 9.14.3.1 >= 9.15.0, < 9.15.1.17 >= 9.16.0, < 9.16.1.28 |
CPE
Remediation
| |
| cisco asa 5512-x firmware | 009.009 009.012 |
CPE
Remediation
| |
| cisco asa 5512-x | All versions |
CPE
Remediation
| |
| cisco asa 5505 firmware | 009.009 009.012 |
CPE
Remediation
| |
| cisco asa 5505 | All versions |
CPE
Remediation
| |
| cisco asa 5515-x firmware | 009.009 009.012 |
CPE
Remediation
| |
| cisco asa 5515-x | All versions |
CPE
Remediation
| |
| cisco asa 5525-x firmware | 009.009 009.012 |
CPE
Remediation
| |
| cisco asa 5525-x | All versions |
CPE
Remediation
| |
| cisco asa 5545-x firmware | 009.009 009.012 |
CPE
Remediation
| |
| cisco asa 5545-x | All versions |
CPE
Remediation
| |
| cisco asa 5555-x firmware | 009.009 009.012 |
CPE
Remediation
| |
| cisco asa 5555-x | All versions |
CPE
Remediation
| |
| cisco asa 5580 firmware | 009.009 009.012 |
CPE
Remediation
| |
| cisco asa 5580 | All versions |
CPE
Remediation
| |
| cisco asa 5585-x firmware | 009.009 009.012 |
CPE
Remediation
| |
| cisco asa 5585-x | All versions |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Aug 16, 2023 | CPE Deprecation Remap | [email protected] |
| Aug 16, 2023 | CPE Deprecation Remap | [email protected] |
| Aug 16, 2023 | CPE Deprecation Remap | [email protected] |
| Aug 16, 2023 | CPE Deprecation Remap | [email protected] |
| Oct 29, 2021 | Initial Analysis | [email protected] |
| Oct 27, 2021 | CVE Modified | [email protected] |