---
id: CVE-2021-1445
title: >-
  Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software
  and Firepower Threat Defense (FTD) Software could allow an unauthenticated,
  remote attacker to cause a denial of service (DoS) condition on an affected
  device
summary: >-
  Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software
  and Firepower Threat Defense (FTD) Software could allow an unauthenticated,
  remote attacker to cause a denial of service (DoS) condition on an affected
  device. …
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'
cwe:
  - CWE-787
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - 'secure_firewall_threat_defense >= 6.5.0, < 6.6.4'
  - 'secure_firewall_threat_defense >= 6.7.0, < 6.7.0.1'
  - 'adaptive_security_appliance_software >= 9.7, < 9.8.4.34'
  - 'adaptive_security_appliance_software >= 9.9, < 9.9.2.85'
  - 'adaptive_security_appliance_software >= 9.10, < 9.12.4.13'
  - 'adaptive_security_appliance_software >= 9.13, < 9.13.1.21'
  - 'adaptive_security_appliance_software >= 9.14, < 9.14.2.8'
  - 'adaptive_security_appliance_software >= 9.15, < 9.15.1.7'
patched:
  - secure_firewall_threat_defense 6.7.0.1
  - adaptive_security_appliance_software 9.15.1.7
published: '2021-04-29'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-1445'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-vpn-dos-fpBcpEcD
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-vpn-dos-fpBcpEcD
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01656
epssPercentile: 0.7558
ingestedAt: '2026-08-18T12:28:06.990Z'
---

## Overview

Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validation of the HTTPS request. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

## Affected

- `secure_firewall_threat_defense >= 6.5.0, < 6.6.4`
- `secure_firewall_threat_defense >= 6.7.0, < 6.7.0.1`
- `adaptive_security_appliance_software >= 9.7, < 9.8.4.34`
- `adaptive_security_appliance_software >= 9.9, < 9.9.2.85`
- `adaptive_security_appliance_software >= 9.10, < 9.12.4.13`
- `adaptive_security_appliance_software >= 9.13, < 9.13.1.21`
- `adaptive_security_appliance_software >= 9.14, < 9.14.2.8`
- `adaptive_security_appliance_software >= 9.15, < 9.15.1.7`

## Remediation

Upgrade past the affected range:

- `secure_firewall_threat_defense 6.7.0.1`
- `adaptive_security_appliance_software 9.15.1.7`
