CVE-2021-1236

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
Configurations

Configuration 1

cpe:2.3:a:cisco:firepower_management_center:2.9.14.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:2.9.15:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:2.9.16:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:2.9.17:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:2.9.14.14:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
cpe:2.3:a:snort:snort:*:*:*:*:*:*:*:*

Information

Published : 2021-01-13 10:15

Updated : 2023-02-19 04:15


NVD link : CVE-2021-1236

Mitre link : CVE-2021-1236

Products Affected
CWE