cbcvebase.
CVE-2021-1573
published 2022-01-11

CVE-2021-1573: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.31%
67.4th percentile
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit this vulnerability by sending a malicious HTTPS request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Affected

14 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance<= 9.7
ciscoadaptive_security_appliance
ciscoadaptive_security_appliance_software>= 9.13 < 9.14.39.14.3
ciscoadaptive_security_appliance_software>= 9.15 < 9.15.1.179.15.1.17
ciscoadaptive_security_appliance_software>= 9.16 < 9.16.1.289.16.1.28
ciscoadaptive_security_appliance_software>= 9.8 < 9.8.4.409.8.4.40
ciscoadaptive_security_appliance_software>= 9.9 < 9.12.4.269.12.4.26
ciscocisco_adaptive_security_appliance_software>= unspecified < 6.4.0.136.4.0.13
ciscocisco_firepower_threat_defense_software>= unspecified < 6.6.56.6.5
ciscofirepower_threat_defense<= 6.2.2
ciscofirepower_threat_defense
ciscofirepower_threat_defense>= 6.2.3 < 6.4.0.136.4.0.13
ciscofirepower_threat_defense>= 6.5.0 < 6.6.56.6.5
ciscofirepower_threat_defense>= 6.7.0 < 6.7.0.36.7.0.3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.