PT-2021-4922 · Cisco · Snort 3+1
Published
2021-10-27
·
Updated
2025-07-07
·
CVE-2021-40116
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Firepower Threat Defense (FTD) with Snort3 configured and either a rule with Block with Reset or Interactive Block with Reset actions configured
Description
The issue is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints. An attacker could exploit this by sending a crafted IP packet to the affected device, potentially causing through traffic to be dropped. This could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Recommendations
For Cisco Firepower Threat Defense (FTD) with Snort3 configured, consider disabling the Block with Reset or Interactive Block with Reset actions until a patch is available.
Restrict access to devices with Snort3 configured to minimize the risk of exploitation.
Avoid using rules with Block with Reset or Interactive Block with Reset actions in Snort3 until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ftd
Snort 3