← Browse

CVE-2021-34790

Low

No strong exploitation signal.

CVSS base
4.7 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
EPSS — probability of exploitation (30 days)
1.1%
65.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-20
Published 2021-10-27 · modified 2026-08-11

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredNNone
User InteractionRRequired
ScopeCChanged
ConfidentialityNNone
IntegrityLLow
AvailabilityNNone

Timeline

Description

Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For more information about these vulnerabilities, see the Details section of this advisory. Note: These vulnerabilities have been publicly discussed as NAT Slipstreaming.

Affected

cisco

References

Official: NVD · CVE.org