Out-of-bounds write in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2021-1504

 

Out-of-bounds write in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2021-1504

Published: April 28, 2021


Vulnerability identifier: #VU52716
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1504
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software VPN interface. A remote non-authenticated attacker can send a specially crafted HTTP request, trigger an out-of-bounds write error and crash the service.

Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.


Affected software

Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2021-1504

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.12, 6.6.4, 6.7.0.2
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.8.4.35, 9.9.2.85, 9.12.4.18, 9.13.1.21, 9.14.2.13, 9.15.1.15

External References

Related Security Bulletins