Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-1476
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2021-1476) was discovered in the Command Line Interface (CLI) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software. The vulnerability was first published on April 28, 2021, affecting ASA Software releases 9.13 and FTD Software releases 6.5 through their respective first fixed releases. This security flaw could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device (Cisco Advisory).

Technical details

The vulnerability stems from insufficient input validation of commands supplied by the user. It has been assigned a CVSS base score of 6.7 with the vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X. The flaw specifically affects the CLI interface, where authenticated users could submit crafted input for specific commands. For Cisco ASA Software, there is no legitimate way to access the underlying root shell, making all ASA Software deployments vulnerable. In FTD Software deployments, the vulnerability only affects multi-instance (MI) mode where Expert Mode must be manually configured (Cisco Advisory).

Impact

A successful exploitation of this vulnerability could allow an attacker to execute commands on the underlying operating system with root privileges. However, to exploit this vulnerability, an attacker must have valid administrator-level credentials. In FTD Software's MI mode, a malicious administrator who hasn't been granted access to the underlying root shell could exploit this vulnerability to bypass that restriction (Cisco Advisory).

Exploitability

The Cisco Product Security Incident Response Team (PSIRT) reported no public announcements or malicious use of the vulnerability at the time of disclosure. The vulnerability was discovered during internal security testing by Ilkin Gasimov of Cisco (Cisco Advisory).

Mitigation and workarounds

Cisco has released software updates to address this vulnerability. For ASA Software, the fixed versions are 9.13.1.21, 9.14.2.13, and 9.15.1.10. For FTD Software, the fixed versions are 6.6.4 and 6.7.0.2. No workarounds are available for this vulnerability. Users are advised to upgrade to the fixed software versions. For FTD Software upgrades, devices managed by Cisco Firepower Management Center (FMC) should use the FMC interface, while those managed by Firepower Device Manager (FDM) should use the FDM interface (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20332CRITICAL9.9
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20336HIGH8.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20333HIGH8.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesSep 16, 2026
CVE-2026-20334HIGH8.4
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesSep 16, 2026
CVE-2026-20335HIGH8.1
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management