SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-1224

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP.

MEDIUM 5.3EPSS 2.00%

Does this matter?

Lower severity and a low EPSS score (2.00%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO connection handshake. An attacker could exploit this vulnerability by sending crafted TFO packets with an HTTP payload through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
2.00% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-693
Affected
cisco/secure firewall management center · cisco/secure firewall threat defense · cisco/ios xe · snort/snort · cisco/meraki mx64 firmware · cisco/meraki mx64w firmware · cisco/meraki mx67 firmware · cisco/meraki mx67c firmware · cisco/meraki mx67w firmware · cisco/meraki mx68 firmware · cisco/meraki mx68cw firmware · cisco/meraki mx68w firmware · cisco/meraki mx100 firmware · cisco/meraki mx84 firmware · cisco/meraki mx250 firmware · cisco/meraki mx450 firmware
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.