CVE-2021-1494
published 2024-11-15CVE-2021-1494: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a…
PriorityP335medium5.8CVSS 3.1
AVNACLPRNUINSCCNILAN
EPSS
1.07%
61.1th percentile
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP.
The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
osv5.8MEDIUM
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-1492
vendor_chrome·2022-04-26·CVSS 6.1
CVE-2022-1492 [MEDIUM] Stable Channel Update for Desktop: CVE-2022-1492
Stable Channel Update for Desktop
CVE-2022-1492: Insufficient data validation in Blink Editing. Reported by Michał Bentkowski of Securitum on 2022-04-11 [$1000][ 1275414 ] Medium CVE-2022-1493: Use after free in Dev Tools
Reported by Zhihua Yao of KunLun Lab on 2021-12-01 [$1000][ 1298122 ] Medium CVE-2022-1494: Insufficient data validation in Trusted Types
Severity: medium
Cisco
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
vendor_cisco·2021-04-28·CVSS 5.8
CVE-2021-1494 [MEDIUM] CWE-693 Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP.
These vulnerabilities are due to incorrect handling of specific HTTP header parameters. An attacker could exploit these vulnerabilities by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudap
Cisco
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1494 Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
CVE-2021-1494: Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. These vulnerabilities are due to incorrect handling of specific HTTP header parameters. An attacker could exploit these vulnerabilities by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.1
CWE: CWE-693, CWE-693
Bug IDs: CSCvv70864, CSCvw19272, CSCvw26645, CSCvv70864, CSCvw19272
OSV
CVE-2021-1494: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a
osv·2024-11-15·CVSS 5.8
CVE-2021-1494 [MEDIUM] CVE-2021-1494: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
GHSA
GHSA-wh72-9gx8-gwhv: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a
ghsa_unreviewed·2024-11-15
CVE-2021-1494 [MEDIUM] CWE-693 GHSA-wh72-9gx8-gwhv: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP.
The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-15
Published