cbcvebase.
CVE-2021-1236
published 2021-01-13

CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.

Affected

22 ranges
VendorProductVersion rangeFixed in
ciscocisco_firepower_threat_defense_software
ciscofirepower_threat_defense< 6.5.0.56.5.0.5
ciscoios_xe< 17.4.117.4.1
ciscoproducts_snort_application_detection_engine_policy
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
craftcmscms>= 3.4.0 < 3.7.143.7.14
fortinetfortimanager
fortinetfortinet
html-to-csv_projecthtml-to-csv0 – 0.1.3
kevinpapstkimai2>= 0 < 1.14.11.14.1
mantisbtmantisbt>= 0 < 2.25.32.25.3
pimcorepimcore>= 0 < 10.1.110.1.1
shuupshuup>= 0.4.2 < 2.11.02.11.0
snortsnort< 2.9.142.9.14
symfonyserializer>= 4.1.0 < 4.4.354.4.35
symfonyserializer>= 5.0.0 < 5.3.125.3.12
symfonysymfony>= 4.1.0 < 4.4.354.4.35
symfonysymfony>= 5.0.0 < 5.3.125.3.12

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM