CVE-2021-1224
Snort vulnerability analysis and mitigation

Overview

Multiple Cisco products are affected by a vulnerability (CVE-2021-1224) with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine. The vulnerability was discovered in January 2021 and affects various Cisco products including Firepower Threat Defense Software, Meraki MX Series devices, and multiple router series (Cisco Advisory).

Technical details

The vulnerability stems from incorrect detection of HTTP payload when it is contained partially within the TFO connection handshake. The vulnerability has been assigned a CVSS base score of 5.8 (Medium severity) with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X (Cisco Advisory).

Impact

A successful exploitation of this vulnerability could allow an attacker to bypass configured file policy for HTTP packets and deliver malicious payloads. This affects the security posture of the network by potentially allowing unauthorized file transfers (Cisco Advisory).

Exploitability

The vulnerability can be exploited by an unauthenticated, remote attacker by sending crafted TFO packets with an HTTP payload through an affected device. As of the advisory publication, Cisco PSIRT was not aware of any public announcements or malicious use of this vulnerability (Cisco Advisory).

Mitigation and workarounds

For Cisco FTD Software Release 6.7.0, a workaround is available when using Snort 3 configuration by enabling built-in rule 129:2 in the intrusion policy and setting the action to Drop instead of Alert. Fixed software versions include Cisco FTD releases 6.4.0.12, 6.6.3, and 6.7.0 for Snort 2 configuration, and Cisco UTD Snort IPS Engine Software for IOS XE versions 16.12.5, 17.3.3, and 17.4.11 (Cisco Advisory).

Community reactions

The vulnerability was reported by Guillermo Muñoz Mozos of BBVA and has been acknowledged in multiple security advisories, including updates from Debian (Debian Advisory).

Additional resources


SourceThis report was generated using AI

Related Snort vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20068MEDIUM5.8
  • Snort logoSnort
  • snort
NoYesMar 04, 2026
CVE-2026-20067MEDIUM5.8
  • Snort logoSnort
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesMar 04, 2026
CVE-2026-20066MEDIUM5.8
  • Snort logoSnort
  • snort
NoYesMar 04, 2026
CVE-2026-20065MEDIUM5.8
  • Snort logoSnort
  • snort
NoYesMar 04, 2026
CVE-2026-20058MEDIUM5.8
  • Snort logoSnort
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management