Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| cisco | ios_xe | 17.4.1 | - |
| cisco | firepower_threat_defense | 6.5.0.5 | - |
| cisco | secure_firewall_management_center |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
8
Affected Products
6
References
cisco / ios_xe
| - |
| - |
| cisco | secure_firewall_management_center | - | - |
| cisco | secure_firewall_management_center | - | - |
| cisco | secure_firewall_management_center | - | - |
| cisco | secure_firewall_management_center | - | - |
| snort | snort | 2.9.14 | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability
Impact