cbcvebase.
CVE-2021-34704
published 2022-01-11

CVE-2021-34704: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit this vulnerability by sending a malicious HTTPS request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance
ciscoadaptive_security_appliance_software>= 9.15 < 9.15.1.179.15.1.17
ciscoadaptive_security_appliance_software>= 9.16 < 9.16.29.16.2
ciscocisco_adaptive_security_appliance_software>= unspecified < 6.4.0.136.4.0.13
ciscocisco_firepower_threat_defense_software>= unspecified < 6.6.56.6.5
ciscofirepower_threat_defense
ciscofirepower_threat_defense>= 6.7.0 < 6.7.0.36.7.0.3