Security News

Cybersecurity news aggregator

🌐
MEDIUM Vulnerabilities Web Discovery

Vulnerability-Lookup

  • What: Multiple vulnerabilities in Cisco products' HTTP MIME Decoder could allow a remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or restart.
  • Impact: Unauthenticated attackers can potentially cause a denial of service or information leakage on vulnerable Cisco products running Snort 3.
  • Affected: Open Source Snort 3 and other Cisco products.
  • Patch: Cisco has released software updates to address these vulnerabilities.
  • Action: Apply the relevant software updates from Cisco.
Read Full Article →

Modal body text goes here. Modal Body Source (Optional) Summary Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities Notes Summary Multiple Cisco products are affected by vulnerabilities in the HTTP Multipurpose Internet Mail Extensions (MIME) Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak possible sensitive information or to restart. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Vulnerable Products For information about which products were affected by these vulnerabilities at the time of publication, see the following sections. Open Source Snort 3 At the time of publication, these vulnerabilities affected Open Source Snort 3. For information about which Snort releases were vulnerable at the time of publication, see the Fixed Software ["#fs"] section of this advisory. For more information on Snort, see the Snort website ["https://www.snort.org/"]. Cisco Secure Firewall Threat Defense Software At the time of publication, these vulnerabilities affected Cisco Secure Firewall Threat Defense (FTD) Software if Snort 3 was configured. For information about which Cisco software releases are vulnerable, see the Fixed Software ["#fs"] section of this advisory. Determine the Snort Configuration on Cisco Secure FTD Software On new installations of Cisco Secure FTD Software releases 7.0.0 and later, Snort 3 is running by default. On devices that were running Cisco Secure FTD Software Release 6.7.0 or earlier and were upgraded to Release 7.0.0 or later, Snort 2 is running by default. To determine if Snort 3 is running on Cisco Secure FTD Software, see Determine the Active Snort Version that Runs on Firepower Threat Defense (FTD) ["https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/220415-determine-the-active-snort-version-that.html"]. Snort 3 must be active for these vulnerabilities to be exploited. Cisco IOS XE Software At the time of publication, these vulnerabilities affected the following Cisco products if they were running a vulnerable release of Unified Threat Defense (UTD) Snort IPS Engine for Cisco IOS XE Software or UTD Engine for Cisco IOS XE SD-WAN Software: 1000 Series Integrated Services Routers (ISRs) 4000 Series ISRs Catalyst 8000V Edge Software Catalyst 8200 Series Edge Platforms Catalyst 8300 Series Edge Platforms Catalyst 8500L Edge Platforms Cloud Services Routers 1000V Integrated Services Virtual Routers Note: UTD is not installed on these devices by default. If the UTD file is not installed, the device is not affected by these vulnerabilities. For information about vulnerable and fixed releases, see the bug IDs at the top of this advisory. Determine Whether UTD Is Enabled To determine whether UTD is enabled on a device, use the show utd engine standard status command. If the output shows a Yes under Running, UTD is enabled. If there is no output, the device is not affected. The following example shows the output on a device that has UTD enabled: Router# show utd engine standard status Engine version : 1.0.19_SV2.9.16.1_XE17.3 Profile : Cloud-Low System memory : Usage : 6.00 % Status : Green Number of engines : 1 Engine Running Health Reason =========================================== Engine(#1): Yes Green None ======================================================= . . . Impact to Cisco Meraki Products At the time of publication, these vulnerabilities affected the following Cisco products if they were running a vulnerable release of Cisco Meraki software: MX64 MX64W MX65 MX65W MX67 MX67C MX67W MX68 MX68CW MX68W MX75 MX84 MX85 MX95 MX100 MX105 MX250 MX400 MX450 MX600 For information about which Cisco software releases were vulnerable at the time of publication, see the Fixed Software ["#fs"] section of this advisory. Impact to Other Cisco Products At the time of publication, these vulnerabilities affected Cisco Cyber Vision. For information about which Cisco software releases were vulnerable at the time of publication, see the Fixed Software ["#fs"] section of this advisory. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information. Products Confirmed Not Vulnerable Only products listed in the Vulnerable Products ["#vp"] section of this advisory are known to be affected by these vulnerabilities. Cisco has confirmed that these vulnerabilities do not affect Open Source Snort 2. Cisco also has confirmed that these vulnerabilities do not affect the following Cisco products: Secure Firewall Adaptive Security Appliance (ASA) Software Secure Firewall Management Center (FMC) Software Umbrella Secure Internet Gateway (SIG) Details The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit anoth

Share this article