Cisco · Snort · CVE-2021-1224
Name of the Vulnerable Software and Affected Versions:
Multiple Cisco products (affected versions not specified)
Description:
The issue is related to a vulnerability in the TCP Fast Open (TFO) protocol when used with the Snort detection engine. This vulnerability could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO connection handshake. An attacker could exploit this vulnerability by sending crafted TFO packets with an HTTP payload through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.