The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3317-1 | snort security update |
Debian DSA |
DSA-5354-1 | snort security update |
EUVD |
EUVD-2021-6961 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload. |
Fri, 15 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco firepower Threat Defense Software Cisco utd Snort Ips Engine Software |
|
| CPEs | cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:utd_snort_ips_engine_software:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cisco
Cisco firepower Threat Defense Software Cisco utd Snort Ips Engine Software |
|
| Metrics |
ssvc
|
Fri, 15 Nov 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured file policy for HTTP packets and deliver a malicious payload. | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-15T21:23:12.943Z
Reserved: 2020-11-13T00:00:00.000Z
Link: CVE-2021-1494
Updated: 2024-11-15T21:23:06.575Z
Status : Deferred
Published: 2024-11-15T17:15:09.423
Modified: 2026-04-15T00:35:42.020
Link: CVE-2021-1494
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD