漏洞信息详情
Cisco Firepower Threat Defense(FTD)和Cisco Adaptive Security Appliances Software(ASA Software)安全漏洞
漏洞简介
Cisco Firepower Threat Defense(FTD)和Cisco Adaptive Security Appliances Software(ASA Software)都是美国思科(Cisco)公司的产品。Cisco Firepower Threat Defense是一套提供下一代防火墙服务的统一软件。Cisco Adaptive Security Appliances Software是一套防火墙和网络安全平台。该平台提供了对数据和网络资源的高度安全的访问等功能。
Cisco Firepower Threat Defense(FTD)和Cisco Adaptive Security Appliances Software(ASA Software) SSL/TLS Denial存在安全漏洞,该漏洞源于配置为使用对象组搜索的受影响设备对网络请求的处理不当。攻击者可以通过向受影响的设备发送特制的网络请求来利用此漏洞。成功的利用可能允许攻击者绕过设备上的访问控制列表 (ACL) 规则,绕过安全保护,并将网络流量发送到未经授权的主机。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-rule-bypass-ejjOgQEY
参考网址
来源:CISCO
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-rule-bypass-ejjOgQEY
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Cisco-ASA-egress-filtrering-bypass-via-IDFW-36744
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3599
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-34787
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021102809
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-rule-bypass-ejjOgQEY
受影响实体
暂无
补丁
- Cisco Firepower Threat Defense(FTD)和Cisco Adaptive Security Appliances Software(ASA Software)安全漏洞的修复措施<!--2021-10-27-->
还没有评论,来说两句吧...