VDB

CVE-2021-34790

CVE-2021-34790 PUBLISHED CVSS 4.699999809265137 MEDIUM

Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For more information about these vulnerabilities, see the Details section of this advisory. Note: These vulnerabilities have been publicly discussed as NAT Slipstreaming.

EPSS 0.47% · 64.8th percentile

Risk Scores

CVSS 3.1
4.699999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
EPSS Score
0.47%
64.8th percentile

Affected Products

VendorProductVersions
ciscoasa_5525-x_firmware009.015, 009.008
ciscoadaptive_security_appliance0
ciscoasa_5505_firmware009.015, 009.008
ciscoasa_5512-x_firmware009.015, 009.008
ciscoasa_5555-x_firmware009.008, 009.015
ciscoasa_5580_firmware009.008, 009.015
ciscoasa_5585-x_firmware009.015, 009.008
ciscofirepower_threat_defense6.5.0, 0, 6.7.0
ciscoasa_5545-x_firmware009.008, 009.015
ciscoasa_5515-x_firmware009.015, 009.008
CiscoCisco Adaptive Security Appliance (ASA) Softwaren/a
ciscoadaptive_security_appliance_software9.13.0, 9.12.0, 9.15.0

Timeline

  • Oct 27, 2021 CVE Published
  • Oct 28, 2021 EPSS Score
  • Dec 23, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 17, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 14, 2022 EPSS Score
  • Jun 9, 2022 EPSS Score
  • Aug 5, 2022 EPSS Score
  • Nov 25, 2022 EPSS Score
  • Jan 20, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›