PT-2021-4718 · Cisco · Cisco Asa+1

Published

2021-10-27

·

Updated

2023-08-16

·

CVE-2021-34791

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified) Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description The issue is related to the incorrect implementation of security checks for standard elements in the File Transfer Protocol (FTP) and Network Address Translation (NAT) feature of the Application Layer Gateway (ALG) in Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) software. This could allow a remote attacker to bypass security restrictions and open unauthorized connections by sending specially crafted FTP traffic through the ALG. The vulnerabilities have been publicly discussed as NAT Slipstreaming.
Recommendations For Cisco Adaptive Security Appliance (ASA) Software, update to a version that includes the fix for this issue. For Cisco Firepower Threat Defense (FTD) Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the ALG to minimize the risk of exploitation.

Fix

Improperly Implemented Security Check for Standard

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-05424
CVE-2021-34791

Affected Products

Cisco Asa
Cisco Ftd