Vulnerability Description
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of SSL/TLS messages when the device performs software-based SSL decryption. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message through an affected device. SSL/TLS messages sent to an affected device do not trigger this vulnerability. A successful exploit could allow the attacker to cause a process to crash. This crash would then trigger a reload of the device. No manual intervention is needed to recover the device after the reload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Firepower Threat Defense | >= 6.3.0, < 6.4.0 |
| Cisco | Firepower Threat Defense Virtual | - |
| Cisco | Asa 5512-X | - |
| Cisco | Asa 5515-X | - |
| Cisco | Asa 5525-X | - |
| Cisco | Asa 5545-X | - |
| Cisco | Asa 5555-X | - |
| Cisco | Firepower 1010 | - |
| Cisco | Firepower 1120 | - |
| Cisco | Firepower 1140 | - |
| Cisco | Firepower 1150 | - |
| Cisco | Firepower 2110 | - |
| Cisco | Firepower 2120 | - |
| Cisco | Firepower 2130 | - |
| Cisco | Firepower 2140 | - |
| Cisco | Isa 3000 | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fVendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fVendor Advisory
FAQ
What is CVE-2021-1402?
CVE-2021-1402 is a vulnerability with a CVSS score of 8.6 (HIGH). A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device...
How severe is CVE-2021-1402?
CVE-2021-1402 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-1402?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Firepower Threat Defense, Cisco Firepower Threat Defense Virtual, Cisco Asa 5512-X, Cisco Asa 5515-X, Cisco Asa 5525-X.