Description

Security researchers have discovered a high severity vulnerability in Cisco ASA (Adaptive Security Appliance) and Cisco FTD (Firepower Threat Defense) firewalls that allows for a denial of service (DoS) attack. The vulnerability is identified as CVE-2021-34704, and it is caused by improper input validation while processing HTTPS requests. An unauthenticated attacker can take advantage of this vulnerability by sending specially crafted HTTPS requests to a vulnerable device, allowing attackers to reload the device and cause a DoS situation. Furthermore, experts claimed that if an attacker effectively interrupts Cisco firewall services, remote users or partners would be unable to access internal devices, significantly impacting corporate operations and making it subject to targeted attacks. In addition, in September 2021, Cisco released urgent software updates to address critical authentication flaw (CVE-2021-34746), which allows an unauthenticated attacker to bypass authentication and log into vulnerable devices as an administrator.