Cisco Security Advisory - Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability

Started by Netwörkheäd, January 18, 2021, 12:16:27 PM

Previous topic - Next topic

Netwörkheäd

Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.


The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.


Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.


This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATq



     
         
Security Impact Rating:  Medium
   
   
       
CVE: CVE-2021-1236
Source: Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
Let's not argue. Let's network!