Unknown
CVE-2021-1224
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-1224
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO connection handshake. An attacker could exploit this vulnerability by sending crafted TFO packets with an HTTP payload through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- cisco,
- snort
Products
- firepower management center 2.9.14.0,
- firepower management center 2.9.15,
- firepower management center 2.9.16,
- firepower management center 2.9.17,
- firepower management center 2.9.18,
- firepower management center 3.0.1,
- firepower threat defense,
- ios xe,
- meraki mx100 firmware -,
- meraki mx250 firmware -,
- meraki mx450 firmware -,
- meraki mx64 firmware -,
- meraki mx64w firmware -,
- meraki mx67 firmware -,
- meraki mx67c firmware -,
- meraki mx67w firmware -,
- meraki mx68 firmware -,
- meraki mx68cw firmware -,
- meraki mx68w firmware -,
- meraki mx84 firmware -,
- snort
References
Advisory
Additional Info
Technical Analysis
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: