cbcvebase.
CVE-2021-1236
published 2021-01-13

CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to…

PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.15%
80.2th percentile
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.

Affected

22 ranges
VendorProductVersion rangeFixed in
ciscocisco_firepower_threat_defense_software
ciscofirepower_threat_defense< 6.5.0.56.5.0.5
ciscoios_xe< 17.4.117.4.1
ciscoproducts_snort_application_detection_engine_policy
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
craftcmscms>= 3.4.0 < 3.7.143.7.14
fortinetfortimanager
fortinetfortinet
html-to-csv_projecthtml-to-csv0 – 0.1.3
kevinpapstkimai2>= 0 < 1.14.11.14.1
mantisbtmantisbt>= 0 < 2.25.32.25.3
pimcorepimcore>= 0 < 10.1.110.1.1
shuupshuup>= 0.4.2 < 2.11.02.11.0
snortsnort< 2.9.142.9.14
symfonyserializer>= 4.1.0 < 4.4.354.4.35
symfonyserializer>= 5.0.0 < 5.3.125.3.12
symfonysymfony>= 4.1.0 < 4.4.354.4.35
symfonysymfony>= 5.0.0 < 5.3.125.3.12

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv3.04.0MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_cisco6.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.