CVE-2021-1402
Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs software-based SSL decryption. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message through an affected device. SSL/TLS messages sent to an affected device do not trigger this vulnerability. A successful exploit could allow the attacker to cause a process to crash. This crash would then trigger a reload of the device. No manual intervention is needed to recover the device after the reload.
Una vulnerabilidad en el controlador de mensajes SSL/TLS basado en software del software Cisco Firepower Threat Defense (FTD) podría permitir a un atacante remoto no autenticado activar una recarga de un dispositivo afectado, resultando en una condición de denegación de servicio (DoS). La vulnerabilidad es debido a una comprobación insuficiente de los mensajes SSL/TLS cuando el dispositivo lleva a cabo el descifrado SSL basado en software. Un atacante podría explotar esta vulnerabilidad mediante el envío de un mensaje SSL/TLS diseñado por medio de un dispositivo afectado. Los mensajes SSL/TLS enviados a un dispositivo afectado no desencadenan esta vulnerabilidad. Una explotación con éxito podría permitir al atacante causar el bloqueo de un proceso. Este bloqueo podría entonces desencadenar una recarga del dispositivo. No es necesaria una intervención manual para recuperar el dispositivo después de la recarga
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2020-11-13 CVE Reserved
- 2021-04-29 CVE Published
- 2024-01-13 EPSS Updated
- 2024-11-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower Threat Defense Virtual Search vendor "Cisco" for product "Firepower Threat Defense Virtual" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5512-x Search vendor "Cisco" for product "Asa 5512-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5515-x Search vendor "Cisco" for product "Asa 5515-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5525-x Search vendor "Cisco" for product "Asa 5525-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5545-x Search vendor "Cisco" for product "Asa 5545-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5555-x Search vendor "Cisco" for product "Asa 5555-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1010 Search vendor "Cisco" for product "Firepower 1010" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1120 Search vendor "Cisco" for product "Firepower 1120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1140 Search vendor "Cisco" for product "Firepower 1140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1150 Search vendor "Cisco" for product "Firepower 1150" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2110 Search vendor "Cisco" for product "Firepower 2110" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2120 Search vendor "Cisco" for product "Firepower 2120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2130 Search vendor "Cisco" for product "Firepower 2130" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2140 Search vendor "Cisco" for product "Firepower 2140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.3.0 < 6.4.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.3.0 < 6.4.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Isa 3000 Search vendor "Cisco" for product "Isa 3000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower Threat Defense Virtual Search vendor "Cisco" for product "Firepower Threat Defense Virtual" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5512-x Search vendor "Cisco" for product "Asa 5512-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5515-x Search vendor "Cisco" for product "Asa 5515-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5525-x Search vendor "Cisco" for product "Asa 5525-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5545-x Search vendor "Cisco" for product "Asa 5545-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5555-x Search vendor "Cisco" for product "Asa 5555-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1010 Search vendor "Cisco" for product "Firepower 1010" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1120 Search vendor "Cisco" for product "Firepower 1120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1140 Search vendor "Cisco" for product "Firepower 1140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1150 Search vendor "Cisco" for product "Firepower 1150" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2110 Search vendor "Cisco" for product "Firepower 2110" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2120 Search vendor "Cisco" for product "Firepower 2120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2130 Search vendor "Cisco" for product "Firepower 2130" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2140 Search vendor "Cisco" for product "Firepower 2140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.6.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Isa 3000 Search vendor "Cisco" for product "Isa 3000" | - | - |
Safe
|