5.8mediumMedium
CVE-2021-34754
Cisco Secure Firewall Management Center
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attacker could exploit these vulnerabilities by sending a crafted ENIP packet to the targeted interface. A successful exploit could allow the attacker to bypass configured access control and intrusion policies that should be activated for the ENIP packet.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 5.8 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N- Weakness
- CWE-284
- Assigned by
- psirt@cisco.com
Dates
- Published
- 2021-10-27
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Cisco Secure Firewall Management Center2.9.12, 2.9.14.0, 2.9.16, 2.9.17, 2.9.18
- Cisco Secure Firewall Threat Defense6.4.0 - 6.4.0.13, 6.6.0 - 6.6.5.1, 6.7.0 - 6.7.0.3, 7.0.0 - 7.0.1
As listed in the NVD configuration data. Not a statement about your estate.