CVE-2021-40116
CVE-2021-40116 is a high-severity vulnerability in Cisco Secure Firewall Management Center with a CVSS 3.x base score of 8.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-241.
Key facts
- Severity: High (CVSS 3.x base score 8.6)
- CVSS v2: 7.1
- EPSS exploit prediction: 1% (70th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-241
- Affected product: Cisco Secure Firewall Management Center
- Published:
- Last modified:
Description
Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints. An attacker could exploit this vulnerability by sending a crafted IP packet to the affected device. A successful exploit could allow the attacker to cause through traffic to be dropped. Note: Only products with Snort3 configured and either a rule with Block with Reset or Interactive Block with Reset actions configured are vulnerable. Products configured with Snort2 are not vulnerable.
Frequently asked questions
- What is CVE-2021-40116?
- Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints. An attacker could exploit this vulnerability by sending a crafted IP packet to the affected device. A successful exploit could allow the attacker to cause through traffic to be dropped. Note: Only products with Snort3 configured and either a rule with Block with Reset or Interactive Block with Reset actions configured are vulnerable. Products configured with Snort2 are not vulnerable.
- How severe is CVE-2021-40116?
- CVE-2021-40116 has a CVSS 3.x base score of 8.6, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2021-40116 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (70th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-40116?
- CVE-2021-40116 primarily affects Cisco Secure Firewall Management Center. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2021-40116?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2021-40116 published?
- CVE-2021-40116 was published on 2021-10-27 and last updated on 2026-08-11.
References
Affected products (3)
- cpe:2.3:a:cisco:secure_firewall_management_center:3.1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:snort:*:*:*:*:*:*:*:*
More vulnerabilities in Cisco Secure Firewall Management Center
- CVE-2026-20131 — Critical (CVSS 10.0): A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could…
- CVE-2025-20265 — Critical (CVSS 10.0): A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could…
- CVE-2024-20424 — Critical (CVSS 9.9): A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software,…
- CVE-2023-20048 — Critical (CVSS 9.9): A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an…
- CVE-2019-16028 — Critical (CVSS 9.8): A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an…
- CVE-2020-3318 — Critical (CVSS 9.8): Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software…
All CVEs affecting Cisco Secure Firewall Management Center →
Other CWE-241 vulnerabilities
- CVE-2022-39064 — High (CVSS 8.1): An attacker sending a single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI bulb blink, and if they replay…
- CVE-2025-63548 — High (CVSS 7.5): An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet…
- CVE-2025-2268 — High (CVSS 7.5): The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted…
- CVE-2022-3029 — High (CVSS 7.5): In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot…
- CVE-2022-24668 — High (CVSS 7.5): A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or…
- CVE-2026-47110 — Medium (CVSS 6.5): Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to…