LiveActive security incident?Get immediate response
CVE Record

CVE-2021-34787: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Identity-Based Rule Bypass Vulnerability

A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. An attacker could exploit this vulnerability by sending a specially crafted network request to an affected device. A successful exploit could allow the attacker to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts.

MediumCVSS 5.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This flaw can let someone send traffic through a Cisco ASA or FTD firewall that should have been blocked. The issue affects identity-based firewall rule processing when object group search is used. Business impact is unauthorized network reachability, not direct code execution or data theft in the CVE description.

Executive priority

Schedule remediation through normal vulnerability management, with faster handling for firewalls controlling sensitive segmentation or external access. The score is medium, but the business risk can be higher where firewall policy is a core compensating control.

Technical view

CVE-2021-34787 is an unauthenticated remote ACL bypass in Cisco ASA Software and Cisco FTD Software IDFW rule processing. The supplied record attributes it to improper handling of network requests on affected devices configured for object group search, classified as CWE-183. CVSS v3.1 is 5.3 with network attack vector, low complexity, no privileges, and low integrity impact.

Likely exposure

Exposure is most likely on Cisco ASA or FTD devices that use identity-based firewall rules and have object group search configured. The supplied bundle does not enumerate affected versions, so product/version matching must be confirmed against Cisco's advisory.

Exploitation context

The bundle describes exploitation by a specially crafted network request that may bypass ACL rules and reach unauthorized hosts. It does not provide evidence of active exploitation, and KEV is false. Treat this as a policy-enforcement weakness requiring configuration and version validation.

Researcher notes

Key conditions are IDFW processing and object group search. The supplied data does not include affected release ranges or a named workaround, so avoid broad product assumptions. Validation should focus on configuration-dependent exposure and whether unauthorized reachability could occur across protected trust boundaries.

Mitigation direction

  • Review Cisco's advisory for affected releases, fixed versions, and supported workarounds.
  • Prioritize remediation on internet-edge and segmentation firewalls protecting sensitive networks.
  • Update or reconfigure affected ASA and FTD systems according to Cisco guidance.
  • Review firewall rules after remediation to confirm intended access boundaries remain enforced.

Validation and detection

  • Inventory Cisco ASA and FTD deployments and record software versions.
  • Identify devices using identity-based firewall rules.
  • Check whether object group search is configured on those devices.
  • Compare versions and configurations against Cisco's advisory.
  • Review flow logs for traffic that contradicts intended ACL or IDFW policy.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-183: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-34787 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N3.91.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.3Medium
CVSS 3.1 vector shape for CVE-2021-34787Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CiscoCisco Adaptive Security Appliance (ASA) Softwaren/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-183 · source CWE mapping

Permissive List of Allowed Inputs

Permissive List of Allowed Inputs represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.