CVE-2021-1493
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to insufficient boundary checks for specific data that is provided to the web services interface of an affected system. An attacker could exploit this vulnerability by sending a malicious HTTP request. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system, which could disclose data fragments or cause the device to reload, resulting in a denial of service (DoS) condition.
EPSS 0.61% · 70.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | * |
| cisco | firepower_threat_defense | 0, 6.5.0, 6.7.0 |
| cisco | adaptive_security_appliance_software | 9.14, 9.8, 9.15 |
Exploit Intelligence
Timeline
- Apr 29, 2021 CVE Published
- Apr 30, 2021 EPSS Score
- Jul 3, 2021 EPSS Score
- Sep 3, 2021 EPSS Score
- Nov 5, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Mar 9, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 10, 2022 EPSS Score
- Jul 11, 2022 EPSS Score
- Sep 12, 2022 EPSS Score
- Nov 14, 2022 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-memc-dos-fncTyYKG advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-cmdinj-vWY5wqZT advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-vpn-dos-fpBcpEcD advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-sipdos-GGwmMerC advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-ssl-decrypt-dos-DdyLuK6c advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-1493 advisory