CVE-2021-1236
published 2021-01-13CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to…
PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.15%
80.2th percentile
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | firepower_threat_defense | < 6.5.0.5 | 6.5.0.5 |
| cisco | ios_xe | < 17.4.1 | 17.4.1 |
| cisco | products_snort_application_detection_engine_policy | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| craftcms | cms | >= 3.4.0 < 3.7.14 | 3.7.14 |
| fortinet | fortimanager | — | — |
| fortinet | fortinet | — | — |
| html-to-csv_project | html-to-csv | 0 – 0.1.3 | — |
| kevinpapst | kimai2 | >= 0 < 1.14.1 | 1.14.1 |
| mantisbt | mantisbt | >= 0 < 2.25.3 | 2.25.3 |
| pimcore | pimcore | >= 0 < 10.1.1 | 10.1.1 |
| shuup | shuup | >= 0.4.2 < 2.11.0 | 2.11.0 |
| snort | snort | < 2.9.14 | 2.9.14 |
| symfony | serializer | >= 4.1.0 < 4.4.35 | 4.4.35 |
| symfony | serializer | >= 5.0.0 < 5.3.12 | 5.3.12 |
| symfony | symfony | >= 4.1.0 < 4.4.35 | 4.4.35 |
| symfony | symfony | >= 5.0.0 < 5.3.12 | 5.3.12 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv3.04.0MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_cisco6.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: drm/amdgpu: Fix a use-after-free
vendor_redhat·2024-03-25·CVSS 5.5
CVE-2021-47142 [MEDIUM] CWE-416 kernel: drm/amdgpu: Fix a use-after-free
kernel: drm/amdgpu: Fix a use-after-free
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix a use-after-free
looks like we forget to set ttm->sg to NULL.
Hit panic below
[ 1235.844104] general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b7b4b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI
[ 1235.989074] Call Trace:
[ 1235.991751] sg_free_table+0x17/0x20
[ 1235.995667] amdgpu_ttm_backend_unbind.cold+0x4d/0xf7 [amdgpu]
[ 1236.002288] amdgpu_ttm_backend_destroy+0x29/0x130 [amdgpu]
[ 1236.008464] ttm_tt_destroy+0x1e/0x30 [ttm]
[ 1236.013066] ttm_bo_cleanup_memtype_use+0x51/0xa0 [ttm]
[ 1236.018783] ttm_bo_release+0x262/0xa50 [ttm]
[ 1236.023547] ttm_bo_put+0x82/0xd0 [ttm]
[ 1236.027766] amdgpu_bo_unref+0x26/0x50 [amdgpu]
[ 1236.032809] amdgpu_amdkf
Fortinet
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and...
vendor_fortinet·2021-09-30·CVSS 3.7
CVE-2021-24016 [LOW] CWE-1236 An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and...
FG-IR-20-190: An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and...
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.
CVEs: CVE-2021-24016
CWEs: CWE-1236
CVSS: 3.7 (low)
Affected products: FortiManager, Fortinet
Cisco
Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
vendor_cisco·2021-04-07·CVSS 6.5
CVE-2021-1474 [MEDIUM] CWE-1236 Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-umbrella-inject-gbZGHP5T
Cisco
Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
vendor_cisco·2021-01-13·CVSS 4.0
CVE-2021-1236 [MEDIUM] CWE-670 Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.
The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://se
Cisco
Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2021-1236 Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
CVE-2021-1236: Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-670, CWE-670
Bug IDs: CSCvs85467, CSCvu21318
Cisco
Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1475 Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
CVE-2021-1475: Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-1236, CWE-74, CWE-1236, CWE-74
Bug IDs: CSCvx27753, CSCvx28555, CSCvx27753, CSCvx28555
Cisco
Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1474 Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
CVE-2021-1474: Cisco Umbrella Link and CSV Formula Injection Vulnerabilities
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-1236, CWE-74, CWE-1236, CWE-74
Bug IDs: CSCvx27753, CSCvx28555, CSCvx27753, CSCvx28555
GHSA
GHSA-hj38-j9jq-rjpp: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker
ghsa_unreviewed·2022-05-24
CVE-2021-1236 [MEDIUM] CWE-670 GHSA-hj38-j9jq-rjpp: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
GHSA
MantisBT CSV Injection unprivileged user access in csv_export.php
ghsa·2022-04-15
CVE-2021-43257 [HIGH] CWE-1236 MantisBT CSV Injection unprivileged user access in csv_export.php
MantisBT CSV Injection unprivileged user access in csv_export.php
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.
GHSA
Improper Neutralization of Formula Elements in a CSV File in Kimai 2
ghsa·2022-04-09
CVE-2021-43515 [HIGH] CWE-1236 Improper Neutralization of Formula Elements in a CSV File in Kimai 2
Improper Neutralization of Formula Elements in a CSV File in Kimai 2
A CSV Injection vulnerablity exists in Kimai Kimai 2 prior to 1.14.1 via a description in a new timesheet.
GHSA
Arbitrary code execution in Magnolia CMS
ghsa·2022-02-12
CVE-2021-46363 [HIGH] CWE-1236 Arbitrary code execution in Magnolia CMS
Arbitrary code execution in Magnolia CMS
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted CSV/XLS file.
GHSA
Improper Neutralization of Formula Elements in a CSV File in html-2-csv
ghsa·2021-11-30
CVE-2021-23654 [MEDIUM] CWE-1236 Improper Neutralization of Formula Elements in a CSV File in html-2-csv
Improper Neutralization of Formula Elements in a CSV File in html-2-csv
This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV file. Through this a malicious actor can embed or generate a malicious link or execute commands via CSV files.
GHSA
CSV Injection in symfony/serializer
ghsa·2021-11-24
CVE-2021-41270 [MEDIUM] CWE-1236 CSV Injection in symfony/serializer
CSV Injection in symfony/serializer
Description
CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. When a spreadsheet program opens a CSV, any cell starting with `=` is interpreted by the software as a formula and could be abused by an attacker.
In Symfony 4.1, we've added the opt-in `csv_escape_formulas` option in `CsvEncoder`, to prefix all cells starting by `=`, `+`, `-` or `@` by a tab `\t`.
Since then, OWASP added 2 chars in that list:
- Tab (0x09)
- Carriage return (0x0D)
This makes our previous prefix char (Tab `\t`) part of the vulnerable characters, and [OWASP suggests](https://owasp.org/www-community/attacks/CSV_Injection) using the single quote `'` for prefixing the value.
Resolution
Symfony now follows the OWASP r
GHSA
CSV Injection Vulnerability
ghsa·2021-10-18
CVE-2021-41824 [HIGH] CWE-1236 CSV Injection Vulnerability
CSV Injection Vulnerability
### Impact
In some circumstances, it was possible to export data in CSV format that could trigger a payload in old versions of Excel.
If you are accepting user input from untrusted sources and will be exporting that data in CSV format from element index pages and there is a chance users will open that on old versions of Excel, then you should update.
### Patches
This has been patched in Craft 3.7.14.
### References
* https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#3714---2021-09-28
* https://twitter.com/craftcmsupdates/status/1442928690145366018
### For more information
If you have any questions or comments about this advisory, email us at [email protected]
Credits: BAE Systems AI Vulnerability Research Team – Azrul Ikhwan Zulkifli
GHSA
CSV injection in shuup
ghsa·2021-09-30
CVE-2021-25962 [HIGH] CWE-1236 CSV injection in shuup
CSV injection in shuup
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed.
GHSA
Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore
ghsa·2021-08-30
CVE-2021-37702 [MEDIUM] CWE-1236 Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore
Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore
### Impact
Data Object CSV import allows formular injection.
### Patches
Problem is patched in 10.1.1
### Workarounds
Apply https://github.com/pimcore/pimcore/pull/9992.patch
### References
https://cwe.mitre.org/data/definitions/1236.html
OSV
CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker
osv·2021-01-13·CVSS 5.3
CVE-2021-1236 [MEDIUM] CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/02/msg00011.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATqhttps://www.debian.org/security/2023/dsa-5354https://lists.debian.org/debian-lts-announce/2023/02/msg00011.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATqhttps://www.debian.org/security/2023/dsa-5354
2021-01-13
Published