PT-2021-1726 · Cisco+1 · Snort+1

Guillermo Muñoz Mozos

·

Published

2021-01-13

·

Updated

2024-12-13

·

CVE-2021-1224

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Multiple Cisco products (affected versions not specified)
Description: The issue is related to a vulnerability in the TCP Fast Open (TFO) protocol when used with the Snort detection engine. This vulnerability could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO connection handshake. An attacker could exploit this vulnerability by sending crafted TFO packets with an HTTP payload through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1678
ALT-PU-2024-16610
BDU:2021-00416
CVE-2021-1224
DLA-3317-1
DSA-5354-1
MGASA-2023-0117

Affected Products

Alt Linux
Snort