HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-34793

CVSS 8.6v3.1pub. 2021-10-27upd. 2026-08-11

A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is due to incorrect handling of certain TCP segments when the affected device is operating in transparent mode. An attacker could exploit this vulnerability by sending a crafted TCP segment through an affected device. A successful exploit could allow the attacker to poison the MAC address tables in adjacent devices, resulting in network disruption.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco Adaptive Security Appliance

    APP
    Cisco
    < 9.8.4.40
  • Cisco Adaptive Security Appliance Software

    OS
    Cisco
    9.15.0 – 9.15.1.17 (excl.)9.16.0 – 9.16.2.3 (excl.)9.9.0 – 9.12.4.29 (excl.)9.13.0 – 9.14.3.9 (excl.)
  • Cisco Asa 5505

    HW
    Cisco
    all versions
  • Cisco Asa 5505 Firmware

    OS
    Cisco
    009.008\(004.025\)
  • Cisco Asa 5512 X

    HW
    Cisco
    all versions
  • Cisco Asa 5512 X Firmware

    OS
    Cisco
    009.008\(004.025\)
  • Cisco Asa 5515 X

    HW
    Cisco
    all versions
  • Cisco Asa 5515 X Firmware

    OS
    Cisco
    009.008\(004.025\)
  • Cisco Asa 5525 X

    HW
    Cisco
    all versions
  • Cisco Asa 5525 X Firmware

    OS
    Cisco
    009.008\(004.025\)
  • Cisco Asa 5545 X

    HW
    Cisco
    all versions
  • Cisco Asa 5545 X Firmware

    OS
    Cisco
    009.008\(004.025\)
  • Cisco Asa 5555 X

    HW
    Cisco
    all versions
  • Cisco Asa 5555 X Firmware

    OS
    Cisco
    009.008\(004.025\)
  • Cisco Asa 5580

    HW
    Cisco
    all versions
  • Cisco Asa 5580 Firmware

    OS
    Cisco
    009.008\(004.025\)
  • Cisco Asa 5585 X

    HW
    Cisco
    all versions
  • Cisco Asa 5585 X Firmware

    OS
    Cisco
    009.008\(004.025\)
  • Cisco Secure Firewall Threat Defense

    APP
    Cisco
    < 6.4.0.136.5.0 – 6.6.5 (excl.)6.7.0 – 6.7.0.3 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2025-20333CRITICAL9.9⚠ KEVPL ✓same product

RCE jako root w Cisco ASA i FTD poprzez podatny serwer VPN web

CVE-2025-20363CRITICAL9.0PL ✓same product

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP

CVE-2024-20412CRITICAL9.3PL ✓same product

Cisco FTD: statyczne konta z zakodowanymi hasłami umożliwiają nieautoryzowany dostęp

CVE-2024-20329CRITICAL9.9PL ✓same product

RCE w podsystemie SSH Cisco ASA — wykonanie poleceń jako root

CVE-2022-20829CRITICAL9.1PL ✓same product

Cisco ASA – brak walidacji autentyczności obrazu ASDM umożliwia RCE