Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-1236.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "17.4.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.5.0.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.9.14.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.9.14.14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.9.15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.9.16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.9.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.9.14"
}
]
}
]