Improper access control in Cisco Systems, Inc products - CVE-2021-34794
Published: October 29, 2021
ASA 5500-X Series Firewalls
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Detailed vulnerability description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality. A remote user can bypass implemented security restrictions and send an SNMPv3 query to an affected device from a host that is not permitted by the SNMPv3 access control list.