CVE-2021-34749
published 2021-08-18CVE-2021-34749: A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the…
PriorityP356high8.6CVSS 3.1
AVNACLPRNUINSCCNIHAN
EPSS
1.68%
74.5th percentile
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised host. This vulnerability is due to inadequate filtering of the SSL handshake. An attacker could exploit this vulnerability by using data from the SSL client hello packet to communicate with an external server. A successful exploit could allow the attacker to execute a command-and-control attack on a compromised host and perform additional data exfiltration attacks.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_web_security_appliance | — | — |
| cisco | firepower_management_center_virtual_appliance_firmware | — | — |
| cisco | firepower_management_center_virtual_appliance_firmware | — | — |
| cisco | firepower_management_center_virtual_appliance_firmware | — | — |
| cisco | firepower_management_center_virtual_appliance_firmware | — | — |
| cisco | ironport_web_security_appliance | — | — |
| cisco | products_server_name_identification_data_exfiltration | — | — |
| cisco | secure_firewall_management_center | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv8.6HIGH
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability
vendor_cisco·2021-08-18·CVSS 5.8
CVE-2021-34749 [MEDIUM] CWE-200 Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability
Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability
A vulnerability in the web filtering features of multiple Cisco products could allow an unauthenticated, remote attacker to bypass web reputation filters and threat detection mechanisms on an affected device and exfiltrate data from a compromised host to a blocked external server.
This vulnerability is due to inadequate inspection of the Server Name Identification (SNI) header in the SSL/TLS handshake. An attacker could exploit this vulnerability by using data from the TLS client hello packet to communicate with a blocked external server. A successful exploit could be used to exfiltrate data from a protected network. The attacker must compromise a host on the network to exfiltrate the sensitive data.
The f
Cisco
Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-34749 Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability
CVE-2021-34749: Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability
A vulnerability in the web filtering features of multiple Cisco products could allow an unauthenticated, remote attacker to bypass web reputation filters and threat detection mechanisms on an affected device and exfiltrate data from a compromised host to a blocked external server. This vulnerability is due to inadequate inspection of the Server Name Identification (SNI) header in the SSL/TLS handshake. An attacker could exploit this vulnerability by using data from the TLS client hello packet to communicate with a blocked external server. A successful exploit could be used to exfiltrate data from a protected network. The attacker must compromise a host on the network to exfiltrate the sensiti
GHSA
GHSA-x64m-mg53-f49j: A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and
ghsa_unreviewed·2022-05-24
CVE-2021-34749 [HIGH] CWE-200 GHSA-x64m-mg53-f49j: A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised host. This vulnerability is due to inadequate filtering of the SSL handshake. An attacker could exploit this vulnerability by using data from the SSL client hello packet to communicate with an external server. A successful exploit could allow the attacker to execute a command-and-control attack on a compromised host and perform additional data exfiltration attacks.
OSV
CVE-2021-34749: A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and
osv·2021-08-18·CVSS 8.6
CVE-2021-34749 [HIGH] CVE-2021-34749: A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised host. This vulnerability is due to inadequate filtering of the SSL handshake. An attacker could exploit this vulnerability by using data from the SSL client hello packet to communicate with an external server. A successful exploit could allow the attacker to execute a command-and-control attack on a compromised host and perform additional data exfiltration attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/02/msg00011.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sni-data-exfil-mFgzXqLNhttps://www.debian.org/security/2023/dsa-5354https://lists.debian.org/debian-lts-announce/2023/02/msg00011.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sni-data-exfil-mFgzXqLNhttps://www.debian.org/security/2023/dsa-5354
2021-08-18
Published