QID 317250

Date Published: 2022-11-07

QID 317250: Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability (cisco-sa-snort-app-bypass-cSBYCATq)

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.

Affected Products
1000 Series Integrated Services Routers (ISRs)
4000 Series Integrated Services Routers (ISRs)
Cloud Services Router 1000V
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-snort-app-bypass-cSBYCATq for more information.

    CVEs related to QID 317250

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-snort-app-bypass-cSBYCATq URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATq