CVE-2021-34794
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could exploit this vulnerability by sending an SNMPv3 query to an affected device from a host that is not permitted by the SNMPv3 access control list. A successful exploit could allow the attacker to send an SNMP query to an affected device and retrieve information from the device. The attacker would need valid credentials to perform the SNMP query.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.94%
- Percentil entre todas las CVEs puntuadas: 59
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (10)
CWE
- CWE-284
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-34794",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2021-34794",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-07T21:44:26.270729Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "Cisco",
"product": "Cisco Adaptive Security Appliance (ASA) Software",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-10-27T19:15:08.613",
"references": [
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-snmpaccess-M6yOweq3",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-snmpaccess-M6yOweq3",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could exploit this vulnerability by sending an SNMPv3 query to an affected device from a host that is not permitted by the SNMPv3 access control list. A successful exploit could allow the attacker to send an SNMP query to an affected device and retrieve information from the device. The attacker would need valid credentials to perform the SNMP query."
},
{
"lang": "es",
"value": "Una vulnerabilidad en la funcionalidad access control functionality del Protocolo simple de Administración de Redes versión 3 (SNMPv3) del software Cisco Adaptive Security Appliance (ASA) y del software Cisco Firepower Threat Defense (FTD) podría permitir a un atacante remoto no autenticado consultar datos SNMP. Esta vulnerabilidad es debido a un control de acceso no eficaz. Un atacante podría explotar esta vulnerabilidad mediante el envío de una consulta SNMPv3 a un dispositivo afectado desde un host que no está permitido por la lista de control de acceso SNMPv3. Una explotación con éxito podría permitir al atacante enviar una consulta SNMP a un dispositivo afectado y recuperar información del dispositivo. El atacante necesitaría credenciales válidas para llevar a cabo la consulta SNMP"
}
],
"lastModified": "2026-08-11T19:33:44.513",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A060F4D-6782-4155-9FA5-817828761645",
"versionEndExcluding": "6.4.0.13",
"versionStartIncluding": "6.4.0"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6BAB496F-F3FF-4188-B191-64ED999CDF1C",
"versionEndExcluding": "6.6.5",
"versionStartIncluding": "6.5.0"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EDBB8D9B-E01E-4816-9327-E9E3B16250B8",
"versionEndExcluding": "6.7.0.1",
"versionStartIncluding": "6.7.0"
},
{
"criteria": "cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD445D8E-B7EE-4E9C-9C09-7B43F9803C61",
"versionEndExcluding": "9.14.2.4",
"versionStartIncluding": "9.14.0"
},
{
"criteria": "cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E757EF32-C843-4CBD-BB5B-37B95D654DA0",
"versionEndExcluding": "9.15.1.7",
"versionStartIncluding": "9.15.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_5512-x_firmware:009.014\\(001\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93DC4984-D57D-41EE-AF97-542B2182F94B"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5512-x_firmware:099.015\\(001.033\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F6A9937-D820-44CB-AFDC-B2AEE4AD9FF5"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5512-x_firmware:099.016\\(001.216\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE50B561-6622-47A2-9FD7-DAAB1EDFD7B4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:asa_5512-x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "08F0F160-DAD2-48D4-B7B2-4818B2526F35"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_5505_firmware:009.014\\(001\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D36FBFA-7472-4B9B-B4B3-39DC1D9723C7"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5505_firmware:099.015\\(001.033\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFAB31A6-829E-4B81-8EBA-01D75C657AEB"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5505_firmware:099.016\\(001.216\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "597300F3-CBB8-49C9-B986-97811729247C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:asa_5505:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8E6A8BB7-2000-4CA2-9DD7-89573CE4C73A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_5515-x_firmware:009.014\\(001\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A370D41C-9F5B-4640-B579-685148482004"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5515-x_firmware:099.015\\(001.033\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1B4A1F2-F41A-4909-B95E-BFE239F080E7"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5515-x_firmware:099.016\\(001.216\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E93BD873-53C3-4A99-B7B5-9222653DB003"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:asa_5515-x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "977D597B-F6DE-4438-AB02-06BE64D71EBE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_5525-x_firmware:009.014\\(001\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03D64251-356E-4EEF-AB33-F6F78B1AA3CD"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5525-x_firmware:099.015\\(001.033\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F3BF9F1-DEE2-4603-B7AA-B447202C5B2C"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5525-x_firmware:099.016\\(001.216\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB4AB255-E7BD-486D-ACED-8E53C9BF2AC2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:asa_5525-x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EB71EB29-0115-4307-A9F7-262394FD9FB0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_5545-x_firmware:009.014\\(001\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DC3B61C-CD0E-4A66-8903-D8659716FDCD"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5545-x_firmware:099.015\\(001.033\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50440DFC-715F-4D99-B2DC-463D0A0EF781"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5545-x_firmware:099.016\\(001.216\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA51E7C8-F369-4FE7-B047-0314838F927F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:asa_5545-x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "57179F60-E330-4FF0-9664-B1E4637FF210"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_5555-x_firmware:009.014\\(001\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "606F7A31-5C85-44F3-A132-0B162BA5370E"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5555-x_firmware:099.015\\(001.033\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC66553A-5F9A-46A7-8D52-527954C26C74"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5555-x_firmware:099.016\\(001.216\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "746C3042-0145-47C6-9C64-80CBF86E0E46"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:asa_5555-x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5535C936-391B-4619-AA03-B35265FC15D7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_5580_firmware:009.014\\(001\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF909D44-8737-41B0-ABEB-A360541DFAC0"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5580_firmware:099.015\\(001.033\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "740FED35-145D-4D9B-8B71-619D39C01235"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5580_firmware:099.016\\(001.216\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D6701C3-E5BF-469A-83D7-85675B607C35"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:asa_5580:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D1E828B8-5ECC-4A09-B2AD-DEDC558713DE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_5585-x_firmware:009.014\\(001\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C803E2D7-B1F8-40BB-853D-39FE048CEB47"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5585-x_firmware:099.015\\(001.033\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AADA1E0D-A7C7-4FF4-B64A-78EBC4F60B86"
},
{
"criteria": "cpe:2.3:o:cisco:asa_5585-x_firmware:099.016\\(001.216\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEC32C2A-352B-4844-9276-1C27E0381107"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:asa_5585-x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "16AE20C2-C77E-4E04-BF13-A48696E52426"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@cisco.com"
}