---
id: CVE-2021-1236
title: >-
  Multiple Cisco products are affected by a vulnerability in the Snort
  application detection engine that could allow an unauthenticated, remote
  attacker to bypass the configured policies on an affected system
summary: >-
  Multiple Cisco products are affected by a vulnerability in the Snort
  application detection engine that could allow an unauthenticated, remote
  attacker to bypass the configured policies on an affected system. The
  vulnerability is due to a…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-670
  - CWE-670
vendor: cisco
product: secure_firewall_management_center
affected:
  - ios_xe < 17.4.1
  - secure_firewall_management_center = 2.9.14.0
  - secure_firewall_management_center = 2.9.14.14
  - secure_firewall_management_center = 2.9.15
  - secure_firewall_management_center = 2.9.16
  - secure_firewall_management_center = 2.9.17
  - secure_firewall_threat_defense < 6.5.0.5
  - snort < 2.9.14
patched:
  - ios_xe 17.4.1
  - secure_firewall_threat_defense 6.5.0.5
  - snort 2.9.14
published: '2021-01-13'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-1236'
references:
  - url: 'https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATq
    label: psirt@cisco.com
  - url: 'https://www.debian.org/security/2023/dsa-5354'
    label: psirt@cisco.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATq
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5354'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02146
epssPercentile: 0.81297
ingestedAt: '2026-08-18T12:28:06.864Z'
---

## Overview

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.

## Affected

- `ios_xe < 17.4.1`
- `secure_firewall_management_center = 2.9.14.0`
- `secure_firewall_management_center = 2.9.14.14`
- `secure_firewall_management_center = 2.9.15`
- `secure_firewall_management_center = 2.9.16`
- `secure_firewall_management_center = 2.9.17`
- `secure_firewall_threat_defense < 6.5.0.5`
- `snort < 2.9.14`

## Remediation

Upgrade past the affected range:

- `ios_xe 17.4.1`
- `secure_firewall_threat_defense 6.5.0.5`
- `snort 2.9.14`
