CVE-2021-1495
published 2021-04-29CVE-2021-1495: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a…
PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.71%
75.0th percentile
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | firepower_threat_defense | < 6.4.0.12 | 6.4.0.12 |
| cisco | firepower_threat_defense | >= 6.5.0 < 6.6.4 | 6.6.4 |
| cisco | firepower_threat_defense | >= 6.7.0 < 6.7.0.2 | 6.7.0.2 |
| cisco | ios_xe | >= 16.12 < 16.12.5 | 16.12.5 |
| cisco | ios_xe | >= 17.1 < 17.3.3 | 17.3.3 |
| cisco | ios_xe | >= 17.4 < 17.4.1 | 17.4.1 |
| cisco | products_snort_http_detection_engine_file_policy | — | — |
| snort | snort | < 2.9.17.1 | 2.9.17.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
vendor_cisco·2021-04-28·CVSS 5.8
CVE-2021-1494 [MEDIUM] CWE-693 Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP.
These vulnerabilities are due to incorrect handling of specific HTTP header parameters. An attacker could exploit these vulnerabilities by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudap
Cisco
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1495 Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
CVE-2021-1495: Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. These vulnerabilities are due to incorrect handling of specific HTTP header parameters. An attacker could exploit these vulnerabilities by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.1
CWE: CWE-693, CWE-693
Bug IDs: CSCvv70864, CSCvw19272, CSCvw26645, CSCvv70864, CSCvw19272
GHSA
GHSA-qp86-f9fh-jg8p: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a
ghsa_unreviewed·2022-05-24
CVE-2021-1495 [MEDIUM] CWE-755 GHSA-qp86-f9fh-jg8p: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
OSV
CVE-2021-1495: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a
osv·2021-04-29·CVSS 5.3
CVE-2021-1495 [MEDIUM] CVE-2021-1495: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
Suricata
ET EXPLOIT VMWare View Planner RCE (CVE-2021-21978) Attempt M1
suricata·2021-03-15·CVSS 9.8
CVE-2021-21978 [CRITICAL] ET EXPLOIT VMWare View Planner RCE (CVE-2021-21978) Attempt M1
ET EXPLOIT VMWare View Planner RCE (CVE-2021-21978) Attempt M1
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT VMWare View Planner RCE (CVE-2021-21978) Attempt M1"; flow:established,to_server; http.request_line; content:"POST /logupload?logMetaData="; startswith; fast_pattern; content:"itrLogPath"; content:"log_upload_wsgi.py"; http.request_body; content:"name=|22|logfile|22 3b|"; reference:url,paper.seebug.org/1495/; reference:url,www.vmware.com/security/advisories/VMSA-2021-0003.html; reference:cve,2021-21978; classtype:attempted-admin; sid:2032009; rev:1; metadata:affected_product VMware, attack_target Server, created_at 2021_03_15, cve CVE_2021_21978, deployment Internal, deployment SSLDecrypt, performance_impact Low, confidence High, signature_severity Majo
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/02/msg00011.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-fp-bp-KfDdcQhchttps://www.debian.org/security/2023/dsa-5354https://lists.debian.org/debian-lts-announce/2023/02/msg00011.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-fp-bp-KfDdcQhchttps://www.debian.org/security/2023/dsa-5354
2021-04-29
Published