CVE-2021-34794
Published on: 10/27/2021 12:00:00 AM UTC
Last Modified on: 11/07/2023 03:36:00 AM UTC
CVE-2021-34794 - advisory for cisco-sa-asaftd-snmpaccess-M6yOweq3
Source: Mitre Source: NIST CVE.ORG Print: PDFCertain versions of Adaptive Security Appliance from Cisco contain the following vulnerability:
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could exploit this vulnerability by sending an SNMPv3 query to an affected device from a host that is not permitted by the SNMPv3 access control list. A successful exploit could allow the attacker to send an SNMP query to an affected device and retrieve information from the device. The attacker would need valid credentials to perform the SNMP query.
- CVE-2021-34794 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.
- The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
- Affected Vendor/Software: Cisco - Cisco Adaptive Security Appliance (ASA) Software version n/a
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | LOW | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SNMP Access Control Vulnerability | tools.cisco.com text/html | CISCO 20211027 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SNMP Access Control Vulnerability |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Adaptive Security Appliance | All | All | All | All |
Operating System | Cisco | Adaptive Security Appliance Software | All | All | All | All |
Hardware | Cisco | Asa 5505 | - | All | All | All |
Operating System | Cisco | Asa 5505 Firmware | 009.014\(001\) | All | All | All |
Operating System | Cisco | Asa 5505 Firmware | 099.015\(001.033\) | All | All | All |
Operating System | Cisco | Asa 5505 Firmware | 099.016\(001.216\) | All | All | All |
Hardware | Cisco | Asa 5512-x | - | All | All | All |
Operating System | Cisco | Asa 5512-x Firmware | 009.014\(001\) | All | All | All |
Operating System | Cisco | Asa 5512-x Firmware | 099.015\(001.033\) | All | All | All |
Operating System | Cisco | Asa 5512-x Firmware | 099.016\(001.216\) | All | All | All |
Hardware | Cisco | Asa 5515-x | - | All | All | All |
Operating System | Cisco | Asa 5515-x Firmware | 009.014\(001\) | All | All | All |
Operating System | Cisco | Asa 5515-x Firmware | 099.015\(001.033\) | All | All | All |
Operating System | Cisco | Asa 5515-x Firmware | 099.016\(001.216\) | All | All | All |
Hardware | Cisco | Asa 5525-x | - | All | All | All |
Operating System | Cisco | Asa 5525-x Firmware | 009.014\(001\) | All | All | All |
Operating System | Cisco | Asa 5525-x Firmware | 099.015\(001.033\) | All | All | All |
Operating System | Cisco | Asa 5525-x Firmware | 099.016\(001.216\) | All | All | All |
Hardware | Cisco | Asa 5545-x | - | All | All | All |
Operating System | Cisco | Asa 5545-x Firmware | 009.014\(001\) | All | All | All |
Operating System | Cisco | Asa 5545-x Firmware | 099.015\(001.033\) | All | All | All |
Operating System | Cisco | Asa 5545-x Firmware | 099.016\(001.216\) | All | All | All |
Hardware | Cisco | Asa 5555-x | - | All | All | All |
Operating System | Cisco | Asa 5555-x Firmware | 009.014\(001\) | All | All | All |
Operating System | Cisco | Asa 5555-x Firmware | 099.015\(001.033\) | All | All | All |
Operating System | Cisco | Asa 5555-x Firmware | 099.016\(001.216\) | All | All | All |
Hardware | Cisco | Asa 5580 | - | All | All | All |
Operating System | Cisco | Asa 5580 Firmware | 009.014\(001\) | All | All | All |
Operating System | Cisco | Asa 5580 Firmware | 099.015\(001.033\) | All | All | All |
Operating System | Cisco | Asa 5580 Firmware | 099.016\(001.216\) | All | All | All |
Hardware | Cisco | Asa 5585-x | - | All | All | All |
Operating System | Cisco | Asa 5585-x Firmware | 009.014\(001\) | All | All | All |
Operating System | Cisco | Asa 5585-x Firmware | 099.015\(001.033\) | All | All | All |
Operating System | Cisco | Asa 5585-x Firmware | 099.016\(001.216\) | All | All | All |
Application | Cisco | Firepower Threat Defense | All | All | All | All |
- cpe:2.3:a:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asa_5505:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5505_firmware:009.014\(001\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5505_firmware:099.015\(001.033\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5505_firmware:099.016\(001.216\):*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asa_5512-x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5512-x_firmware:009.014\(001\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5512-x_firmware:099.015\(001.033\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5512-x_firmware:099.016\(001.216\):*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asa_5515-x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5515-x_firmware:009.014\(001\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5515-x_firmware:099.015\(001.033\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5515-x_firmware:099.016\(001.216\):*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asa_5525-x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5525-x_firmware:009.014\(001\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5525-x_firmware:099.015\(001.033\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5525-x_firmware:099.016\(001.216\):*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asa_5545-x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5545-x_firmware:009.014\(001\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5545-x_firmware:099.015\(001.033\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5545-x_firmware:099.016\(001.216\):*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asa_5555-x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5555-x_firmware:009.014\(001\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5555-x_firmware:099.015\(001.033\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5555-x_firmware:099.016\(001.216\):*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asa_5580:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5580_firmware:009.014\(001\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5580_firmware:099.015\(001.033\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5580_firmware:099.016\(001.216\):*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asa_5585-x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5585-x_firmware:009.014\(001\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5585-x_firmware:099.015\(001.033\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:asa_5585-x_firmware:099.016\(001.216\):*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
@CVEreport | CVE-2021-34794 : A vulnerability in the Simple Network Management Protocol version 3 SNMPv3 access control func… twitter.com/i/web/status/1… | 2021-10-27 19:11:07 |
@softek_jp | Cisco ASA Software の SNMPv3 アクセス制御機能の処理に SNMP クエリを実行される問題 (CVE-2021-34794) [40361] sid.softek.jp/content/show/4… #SIDfm #脆弱性情報 | 2021-10-28 07:30:50 |