CVE-2021-34749

Description

A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised host. This vulnerability is due to inadequate filtering of the SSL handshake. An attacker could exploit this vulnerability by using data from the SSL client hello packet to communicate with an external server. A successful exploit could allow the attacker to execute a command-and-control attack on a compromised host and perform additional data exfiltration attacks.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
EPSS Score
Exploitation Probability
2.196

Associated Vulnerability

VulnerabilityOS Platform
snort security update(DSA-5354-1) snort_2.9.20-0+deb11u1_amd64.debLinux
snort security update(DSA-5354-1) snort_2.9.20-0+deb11u1_i386.debLinux
Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability For Cisco Firepower Threat Defense SoftwareNCM
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-34749)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706067Security Update for Cisco Firepower Threat Defense Software Gibraltar-16.12.5

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234