QID 317062
Date Published: 2021-09-27
QID 317062: Cisco Internetwork Operating System (IOS XE) Software Zone-Based Policy Firewall ICMP and UDP Inspection Vulnerability (cisco-sa-zbfw-pP9jfzwL)
A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated,
remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic.
Affected Products
Cisco IOS XE Software if it had either of the following combinations of features enabled:
Zone-Based Policy Firewall with UTD (either the Snort intrusion prevention system [IPS] or web URL filtering)
Zone-Based Policy Firewall with AppQoE
Note: Potential detection as cannot determine vulnerable configurations.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to inject traffic through the Zone-Based Policy Firewall,
resulting in traffic being dropped because it is incorrectly classified or in incorrect reporting figures being produced by high-speed logging (HSL).
Customers are advised to refer to cisco-sa-zbfw-pP9jfzwL for more information.
- cisco-sa-zbfw-pP9jfzwL -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-zbfw-pP9jfzwL
CVEs related to QID 317062
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-zbfw-pP9jfzwL |
|