CVE-2021-1402
published 2021-04-29CVE-2021-1402: A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker…
PriorityP347high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.39%
70.2th percentile
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs software-based SSL decryption. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message through an affected device. SSL/TLS messages sent to an affected device do not trigger this vulnerability. A successful exploit could allow the attacker to cause a process to crash. This crash would then trigger a reload of the device. No manual intervention is needed to recover the device after the reload.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | secure_firewall_threat_defense | >= 6.3.0 < 6.4.0 | 6.4.0 |
| cisco | secure_firewall_threat_defense | >= 6.5.0 < 6.6.0 | 6.6.0 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Firepower Threat Defense TLS Message memory corruption (cisco-sa-ftd-ssl-decrypt-dos-DdyLuK6c)
vuldb·2026-08-12·CVSS 8.6
CVE-2021-1402 [HIGH] Cisco Firepower Threat Defense TLS Message memory corruption (cisco-sa-ftd-ssl-decrypt-dos-DdyLuK6c)
A vulnerability was found in Cisco Firepower Threat Defense. It has been declared as critical. The affected element is an unknown function of the component TLS Message Handler. Executing a manipulation can lead to memory corruption.
The identification of this vulnerability is CVE-2021-1402. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-pmvv-gfvh-28f5: A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote
ghsa_unreviewed·2022-05-24
CVE-2021-1402 [HIGH] CWE-119 GHSA-pmvv-gfvh-28f5: A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs software-based SSL decryption. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message through an affected device. SSL/TLS messages sent to an affected device do not trigger this vulnerability. A successful exploit could allow the attacker to cause a process to crash. This crash would then trigger a reload of the device. No manual intervention is needed to recover the device after the reload.
Cisco
Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
vendor_cisco·2021-04-28·CVSS 8.6
CVE-2021-1402 [HIGH] CWE-119 Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs software-based SSL decryption. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message through an affected device. SSL/TLS messages sent to an affected device do not trigger this vulnerability. A successful exploit could allow the attacker to cause a process to crash. This crash would then trigger a reload of the device. No man
Cisco
Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2021-1402 Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
CVE-2021-1402: Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs software-based SSL decryption. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message through an affected device. SSL/TLS messages sent to an affected device do not trigger this vulnerability. A successful exploit could allow the attacker to cause a process to crash. This crash would then trigger a reload of the d
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
blogs_talos·2022-02-24·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
## Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
Claudio Bozzato of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered multiple vulnerabilities in the Gerbv file viewing software that could allow an attacker to execute arbitrary remote code or disclose sensitive information.
Gerbv is an open-source software that allows users to view RS-274X Gerber files, Excellon drill files and pick-n-place files — all common file formats used to display layers of a circuit board and other computer parts. All of these vulnerabilities exist in the function that allows Gerbv to open Gerber files. Gerbv can be used as a standalone GUI application, or as a library.
TALOS-2021-1402 (CVE-2021-40391), TALOS-2021-1404 (CVE-202
Talos
Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
blogs_talos·2022-02-24·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
Claudio Bozzato of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered multiple vulnerabilities in the Gerbv file viewing software that could allow an attacker to execute arbitrary remote code or disclose sensitive information.
Gerbv is an open-source software that allows users to view RS-274X Gerber files, Excellon drill files and pick-n-place files — all common file formats used to display layers of a circuit board and other computer parts. All of these vulnerabilities exist in the function that allows Gerbv to open Gerber files. Gerbv can be used as a standalone GUI application, or as a library.
TALOS-2021-1402 (CVE-2021-40391), TALOS-2021-1404 (CVE-2021-40393), TALOS-2021-1405 (CVE-2021-40394) and TALOS-2021-1415 (CVE-2021-40401) could all be triggered if a
2021-04-29
Published