CVE-2021-1236
בינונית 5.3
תיאור (מקור, אנגלית)
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - CWE
- CWE-670
מוצרים מושפעים
cisco: ios xe; cisco: 1100-4p integrated services router; cisco: 1100-8p integrated services router; cisco: 1101-4p integrated services router; cisco: 1109-2p integrated services router; cisco: 1109-4p integrated services router; cisco: 1111x-8p integrated services router; cisco: 4221 integrated services router; cisco: 4321 integrated services router; cisco: 4331 integrated services router; cisco: 4351 integrated services router; cisco: 4431 integrated services router; cisco: 4451-x integrated services router; cisco: 4461 integrated services router; cisco: csr 1000v
קישורים
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html
- https://www.debian.org/security/2023/dsa-5354
- https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html
- https://www.debian.org/security/2023/dsa-5354