QID 317250
Date Published: 2022-11-07
QID 317250: Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability (cisco-sa-snort-app-bypass-cSBYCATq)
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.
Affected Products
1000 Series Integrated Services Routers (ISRs)
4000 Series Integrated Services Routers (ISRs)
Cloud Services Router 1000V
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network.
Solution
Customers are advised to refer to cisco-sa-snort-app-bypass-cSBYCATq for more information.
Vendor References
- cisco-sa-snort-app-bypass-cSBYCATq -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-app-bypass-cSBYCATq
CVEs related to QID 317250
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-snort-app-bypass-cSBYCATq |
|