Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2021-34787
Published: October 28, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists in the identity-based firewall (IDFW) rule processing feature. A remote attacker can send a specially crafted network request to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts.
Affected software
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2021-34787
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.8.4.40, 9.12.4.25, 9.14.3.1, 9.15.1.17, 9.16.1.28