← לוח פגיעויות

CVE-2021-1236

בינונית 5.3

תיאור (מקור, אנגלית)

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.

מדדים

CVSS 3.1
5.3 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE
CWE-670

מוצרים מושפעים

cisco: ios xe; cisco: 1100-4p integrated services router; cisco: 1100-8p integrated services router; cisco: 1101-4p integrated services router; cisco: 1109-2p integrated services router; cisco: 1109-4p integrated services router; cisco: 1111x-8p integrated services router; cisco: 4221 integrated services router; cisco: 4321 integrated services router; cisco: 4331 integrated services router; cisco: 4351 integrated services router; cisco: 4431 integrated services router; cisco: 4451-x integrated services router; cisco: 4461 integrated services router; cisco: csr 1000v

קישורים