Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2021-1224

Disclosure Date: January 13, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO connection handshake. An attacker could exploit this vulnerability by sending crafted TFO packets with an HTTP payload through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
5.3 Medium
Impact Score:
1.4
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
Low
Availability (A):
None

General Information

Vendors

  • cisco,
  • snort

Products

  • firepower management center 2.9.14.0,
  • firepower management center 2.9.15,
  • firepower management center 2.9.16,
  • firepower management center 2.9.17,
  • firepower management center 2.9.18,
  • firepower management center 3.0.1,
  • firepower threat defense,
  • ios xe,
  • meraki mx100 firmware -,
  • meraki mx250 firmware -,
  • meraki mx450 firmware -,
  • meraki mx64 firmware -,
  • meraki mx64w firmware -,
  • meraki mx67 firmware -,
  • meraki mx67c firmware -,
  • meraki mx67w firmware -,
  • meraki mx68 firmware -,
  • meraki mx68cw firmware -,
  • meraki mx68w firmware -,
  • meraki mx84 firmware -,
  • snort
Technical Analysis