CVE-2021-1489
Published on: 04/29/2021 12:00:00 AM UTC
Last Modified on: 05/09/2021 02:41:00 AM UTC
CVE-2021-1489 - advisory for cisco-sa-fdm-dos-nFES8xTN
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Firepower 1010 from Cisco contain the following vulnerability:
A vulnerability in filesystem usage management for Cisco Firepower Device Manager (FDM) Software could allow an authenticated, remote attacker to exhaust filesystem resources, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to the insufficient management of available filesystem resources. An attacker could exploit this vulnerability by uploading files to the device and exhausting available filesystem resources. A successful exploit could allow the attacker to cause database errors and cause the device to become unresponsive to web-based management. Manual intervention is required to free filesystem resources and return the device to an operational state.
- CVE-2021-1489 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Firepower Threat Defense Software version n/a
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Firepower Device Manager Software Filesystem Space Exhaustion Denial of Service Vulnerability | tools.cisco.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Cisco | Firepower 1010 | - | All | All | All |
Hardware
| Cisco | Firepower 1120 | - | All | All | All |
Hardware
| Cisco | Firepower 1140 | - | All | All | All |
Hardware
| Cisco | Firepower 1150 | - | All | All | All |
Hardware
| Cisco | Firepower 2110 | - | All | All | All |
Hardware
| Cisco | Firepower 2120 | - | All | All | All |
Hardware
| Cisco | Firepower 2130 | - | All | All | All |
Hardware
| Cisco | Firepower 2140 | - | All | All | All |
Hardware
| Cisco | Firepower 4110 | - | All | All | All |
Hardware
| Cisco | Firepower 4112 | - | All | All | All |
Hardware
| Cisco | Firepower 4115 | - | All | All | All |
Hardware
| Cisco | Firepower 4120 | - | All | All | All |
Hardware
| Cisco | Firepower 4125 | - | All | All | All |
Hardware
| Cisco | Firepower 4140 | - | All | All | All |
Hardware
| Cisco | Firepower 4145 | - | All | All | All |
Hardware
| Cisco | Firepower 4150 | - | All | All | All |
Hardware
| Cisco | Firepower 9300 | - | All | All | All |
Application | Cisco | Firepower Device Manager | All | All | All | All |
- cpe:2.3:h:cisco:firepower_1010:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_1120:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_1140:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_1150:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_2110:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_2120:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_2130:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_2140:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4110:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4112:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4115:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4120:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4125:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4140:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4145:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4150:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_9300:-:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_device_manager:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-1489 | 2021-04-29 18:41:36 |