5.3mediumMedium

CVE-2021-1236

Cisco Ios Xe

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
5.3 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-670
Assigned by
psirt@cisco.com

Dates

Published
2021-01-13
Last modified
2026-08-11
Sources
NVD

Affected products

  • Cisco Ios Xe- 17.4.1
  • Cisco 1100-4p Integrated Services Routerall versions
  • Cisco 1100-8p Integrated Services Routerall versions
  • Cisco 1101-4p Integrated Services Routerall versions
  • Cisco 1109-2p Integrated Services Routerall versions
  • Cisco 1109-4p Integrated Services Routerall versions
  • Cisco 1111x-8p Integrated Services Routerall versions
  • Cisco 4221 Integrated Services Routerall versions
  • Cisco 4321 Integrated Services Routerall versions
  • Cisco 4331 Integrated Services Routerall versions
  • Cisco 4351 Integrated Services Routerall versions
  • Cisco 4431 Integrated Services Routerall versions

As listed in the NVD configuration data. Not a statement about your estate.

References