CVE-2021-1236Medium· 5.3▾ SunlitMultiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.1%
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
ios_xe < 17.4.1secure_firewall_management_center = 2.9.14.0secure_firewall_management_center = 2.9.14.14secure_firewall_management_center = 2.9.15secure_firewall_management_center = 2.9.16secure_firewall_management_center = 2.9.17secure_firewall_threat_defense < 6.5.0.5snort < 2.9.14Upgrade past the affected range:
ios_xe 17.4.1secure_firewall_threat_defense 6.5.0.5snort 2.9.14Connected by shared product, vendor, weakness, or advisory.
CVE-2021-1224Medium· 5.8Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP
CVE-2021-1223High· 7.5Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP
CVE-2020-3315Medium· 5.3Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system
CVE-2026-20044Medium· 6.0A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrict…
CVE-2020-3550High· 8.1A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to perform directory traversal and access directories…
CVE-2020-3549High· 8.1A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash