← Back

CVE-2021-1501

nvd nist
Published: Apr 29, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition.The vulnerability is due to a crash that occurs during a hash lookup for a SIP pinhole connection. An attacker could exploit this vulnerability by sending crafted SIP traffic through an affected device. A successful exploit could allow the attacker to cause a crash and reload of the affected device.

Affected (9)

2 products
Firepower Threat Defense
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
From 9.10 to 9.12.4.18
From 9.13 to 9.13.1.21
From 9.14 to 9.14.2.13
From 9.15 to 9.15.1.15
From 9.8 to 9.8.4.34
From 9.9 to 9.9.2.85
Cisco
From 6.2.2 to 6.4.0.12
From 6.5.0 to 6.6.4
From 6.7.0 to 6.7.0.2

Timeline

No history available yet.