CVE-2021-34794

medium Cisco
CVSS v3 Base Score
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.9%
Exploitation probability in 30 days
Top 43% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
Low
Availability
None
Published: October 27, 2021 (1775 days ago)
Last Modified: August 11, 2026
Vendor: Cisco
Source: NVD

Description

A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could exploit this vulnerability by sending an SNMPv3 query to an affected device from a host that is not permitted by the SNMPv3 access control list. A successful exploit could allow the attacker to send an SNMP query to an affected device and retrieve information from the device. The attacker would need valid credentials to perform the SNMP query.

CWE

CWE-284

Affected Products

cisco secure firewall threat defensecisco adaptive security appliance softwarecisco asa 5512-x firmwarecisco asa 5505 firmwarecisco asa 5515-x firmwarecisco asa 5525-x firmwarecisco asa 5545-x firmwarecisco asa 5555-x firmwarecisco asa 5580 firmwarecisco asa 5585-x firmware

References