CVE-2021-1224
CVE-2021-1224 is a medium-severity vulnerability in Cisco Secure Firewall Management Center with a CVSS 3.x base score of 5.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-693.
Key facts
- Severity: Medium (CVSS 3.x base score 5.8)
- CVSS v2: 5.0
- EPSS exploit prediction: 2% (79th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-693
- Affected product: Cisco Secure Firewall Management Center
- Published:
- Last modified:
Description
Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO connection handshake. An attacker could exploit this vulnerability by sending crafted TFO packets with an HTTP payload through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.
Frequently asked questions
- What is CVE-2021-1224?
- Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO connection handshake. An attacker could exploit this vulnerability by sending crafted TFO packets with an HTTP payload through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.
- How severe is CVE-2021-1224?
- CVE-2021-1224 has a CVSS 3.x base score of 5.8, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2021-1224 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (79th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-1224?
- CVE-2021-1224 primarily affects Cisco Secure Firewall Management Center. In total, 21 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2021-1224?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-1224 published?
- CVE-2021-1224 was published on 2021-01-13 and last updated on 2026-08-11.
References
- https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-tfo-bypass-MmzZrtes
- https://www.debian.org/security/2023/dsa-5354
Affected products (21)
- cpe:2.3:a:cisco:secure_firewall_management_center:2.9.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_management_center:2.9.15:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_management_center:2.9.16:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_management_center:2.9.17:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_management_center:2.9.18:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_management_center:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
- cpe:2.3:a:snort:snort:*:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx64_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx64w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx67_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx67c_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx67w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx68_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx68cw_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx68w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx100_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx84_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx250_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:meraki_mx450_firmware:-:*:*:*:*:*:*:*
More vulnerabilities in Cisco Secure Firewall Management Center
- CVE-2026-20131 — Critical (CVSS 10.0): A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could…
- CVE-2025-20265 — Critical (CVSS 10.0): A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could…
- CVE-2024-20424 — Critical (CVSS 9.9): A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software,…
- CVE-2023-20048 — Critical (CVSS 9.9): A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an…
- CVE-2019-16028 — Critical (CVSS 9.8): A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an…
- CVE-2020-3318 — Critical (CVSS 9.8): Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software…
All CVEs affecting Cisco Secure Firewall Management Center →
Other CWE-693 (Protection Mechanism Failure) vulnerabilities
- CVE-2026-75874 — Critical (CVSS 10.0): Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
- CVE-2026-47140 — Critical (CVSS 10.0): vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins…
- CVE-2026-34208 — Critical (CVSS 10.0): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects…
- CVE-2026-34938 — Critical (CVSS 10.0): PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs…
- CVE-2026-2761 — Critical (CVSS 10.0): Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33,…
- CVE-2022-32845 — Critical (CVSS 10.0): This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS…
Browse all CWE-693 (Protection Mechanism Failure) vulnerabilities →