Improper Enforcement of Message Integrity During Transmission in a Communication Channel in Cisco Systems, Inc products - CVE-2021-34793
Published: October 28, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the TCP Normalizer when handling certain TCP segments. A remote attacker can send a specially crafted TCP segment through an affected device and poison MAC address tables.
Successful exploitation of the vulnerability may allow an attacker to perform a denial of service attack but requires the affected device to be operating in transparent mode.
Affected software
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2021-34793
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.8.4.40, 9.12.4.24, 9.14.2.15, 9.15.1.15