---
id: CVE-2021-1224
title: >-
  Multiple Cisco products are affected by a vulnerability with TCP Fast Open
  (TFO) when used in conjunction with the Snort detection engine that could
  allow an unauthenticated, remote attacker to bypass a configured file policy
  for HTTP
summary: >-
  Multiple Cisco products are affected by a vulnerability with TCP Fast Open
  (TFO) when used in conjunction with the Snort detection engine that could
  allow an unauthenticated, remote attacker to bypass a configured file policy
  for HTTP. T…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-693
vendor: cisco
product: secure_firewall_management_center
affected:
  - secure_firewall_management_center = 2.9.14.0
  - secure_firewall_management_center = 2.9.15
  - secure_firewall_management_center = 2.9.16
  - secure_firewall_management_center = 2.9.17
  - secure_firewall_management_center = 2.9.18
  - secure_firewall_management_center = 3.0.1
  - secure_firewall_threat_defense < 6.7.0
  - ios_xe < 17.4.1
  - snort < 2.9.17
  - meraki_mx64_firmware
  - meraki_mx64w_firmware
  - meraki_mx67_firmware
  - meraki_mx67c_firmware
  - meraki_mx67w_firmware
  - meraki_mx68_firmware
  - meraki_mx68cw_firmware
  - meraki_mx68w_firmware
  - meraki_mx100_firmware
  - meraki_mx84_firmware
  - meraki_mx250_firmware
  - meraki_mx450_firmware
patched:
  - secure_firewall_threat_defense 6.7.0
  - ios_xe 17.4.1
  - snort 2.9.17
published: '2021-01-13'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-1224'
references:
  - url: 'https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-tfo-bypass-MmzZrtes
    label: psirt@cisco.com
  - url: 'https://www.debian.org/security/2023/dsa-5354'
    label: psirt@cisco.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-tfo-bypass-MmzZrtes
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5354'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02005
epssPercentile: 0.80009
ingestedAt: '2026-08-18T12:28:06.808Z'
---

## Overview

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO connection handshake. An attacker could exploit this vulnerability by sending crafted TFO packets with an HTTP payload through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.

## Affected

- `secure_firewall_management_center = 2.9.14.0`
- `secure_firewall_management_center = 2.9.15`
- `secure_firewall_management_center = 2.9.16`
- `secure_firewall_management_center = 2.9.17`
- `secure_firewall_management_center = 2.9.18`
- `secure_firewall_management_center = 3.0.1`
- `secure_firewall_threat_defense < 6.7.0`
- `ios_xe < 17.4.1`
- `snort < 2.9.17`
- `meraki_mx64_firmware`
- `meraki_mx64w_firmware`
- `meraki_mx67_firmware`
- `meraki_mx67c_firmware`
- `meraki_mx67w_firmware`
- `meraki_mx68_firmware`
- `meraki_mx68cw_firmware`
- `meraki_mx68w_firmware`
- `meraki_mx100_firmware`
- `meraki_mx84_firmware`
- `meraki_mx250_firmware`
- `meraki_mx450_firmware`

## Remediation

Upgrade past the affected range:

- `secure_firewall_threat_defense 6.7.0`
- `ios_xe 17.4.1`
- `snort 2.9.17`
