PT-2021-4999 · Cisco · Cisco Ftd

Published

2021-10-27

·

Updated

2021-10-29

·

CVE-2021-34781

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description The issue is related to the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software. It is due to a lack of proper error handling when an SSH session fails to be established. An attacker could exploit this by sending a high rate of crafted SSH connections to the instance, potentially causing resource exhaustion and a denial of service (DoS) condition on the affected device. The device must be manually reloaded to recover.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05764
CVE-2021-34781

Affected Products

Cisco Ftd