CVE-2021-45098
It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden URL. The server will ignore the RST ACK and send the response HTTP packet for the client's request. These packets will not trigger a Suricata reject action.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.82% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- oisf/suricata · debian/debian linux
- Source
- cve@mitre.org
References
- https://forum.suricata.io/t/suricata-6-0-4-and-5-0-8-released/1942Release Notes, Vendor Advisory
- https://github.com/OISF/suricata/commit/50e2b973eeec7172991bf8f544ab06fb782b97dfPatch, Third Party Advisory
- https://github.com/OISF/suricata/releasesRelease Notes, Third Party Advisory
- https://redmine.openinfosecfoundation.org/issues/4710Exploit, Issue Tracking, Patch, Vendor Advisory
- https://forum.suricata.io/t/suricata-6-0-4-and-5-0-8-released/1942Release Notes, Vendor Advisory
- https://github.com/OISF/suricata/commit/50e2b973eeec7172991bf8f544ab06fb782b97dfPatch, Third Party Advisory
- https://github.com/OISF/suricata/releasesRelease Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/03/msg00029.html
- https://redmine.openinfosecfoundation.org/issues/4710Exploit, Issue Tracking, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.