{"id":"CVE-2021-1236","title":"Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system","summary":"Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-670","CWE-670"],"vendor":"cisco","product":"secure_firewall_management_center","affected":["ios_xe < 17.4.1","secure_firewall_management_center = 2.9.14.0","secure_firewall_management_center = 2.9.14.14","secure_firewall_management_center = 2.9.15","secure_firewall_management_center = 2.9.16","secure_firewall_management_center = 2.9.17","secure_firewall_threat_defense < 6.5.0.5","snort < 2.9.14"],"patched":["ios_xe 17.4.1","secure_firewall_threat_defense 6.5.0.5","snort 2.9.14"],"published":"2021-01-13","updated":"2026-08-11","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-1236","references":[{"url":"https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html","label":"psirt@cisco.com"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATq","label":"psirt@cisco.com"},{"url":"https://www.debian.org/security/2023/dsa-5354","label":"psirt@cisco.com"},{"url":"https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATq","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2023/dsa-5354","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02146,"epssPercentile":0.81044,"ingestedAt":"2026-08-18T12:28:06.864Z","slug":"CVE-2021-1236","body":"## Overview\n\nMultiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.\n\n## Affected\n\n- `ios_xe < 17.4.1`\n- `secure_firewall_management_center = 2.9.14.0`\n- `secure_firewall_management_center = 2.9.14.14`\n- `secure_firewall_management_center = 2.9.15`\n- `secure_firewall_management_center = 2.9.16`\n- `secure_firewall_management_center = 2.9.17`\n- `secure_firewall_threat_defense < 6.5.0.5`\n- `snort < 2.9.14`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ios_xe 17.4.1`\n- `secure_firewall_threat_defense 6.5.0.5`\n- `snort 2.9.14`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.2,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}