CVE-2021-1445
Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
EPSS 0.31% · 54.7th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | firepower_threat_defense | 6.5.0, 6.7.0 |
| cisco | adaptive_security_appliance_software | 9.13, 9.14, 9.15 |
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | n/a |
Exploit Intelligence
Timeline
- Apr 29, 2021 CVE Published
- Apr 30, 2021 EPSS Score
- Jul 3, 2021 EPSS Score
- Sep 3, 2021 EPSS Score
- Nov 5, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Mar 9, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 10, 2022 EPSS Score
- Jul 11, 2022 EPSS Score
- Sep 12, 2022 EPSS Score
- Nov 14, 2022 EPSS Score
References
- 20210428 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services VPN Denial of Service Vulnerabilities vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-1445 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-memc-dos-fncTyYKG advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-cmdinj-vWY5wqZT advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-sipdos-GGwmMerC advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-ssl-decrypt-dos-DdyLuK6c advisory