CVE-2021-34749 (CNNVD-202108-1648)
中文标题:
Cisco Firepower Threat Defense 信息泄露漏洞
英文标题:
Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability
漏洞描述
中文描述:
Cisco Firepower Threat Defense(FTD)是美国思科(Cisco)公司的一套提供下一代防火墙服务的统一软件。 Cisco 多款产品存在信息泄露漏洞,该漏洞源于 SSL 握手的过滤不足。Cisco Web安全设备(WSA)、Cisco火力威胁防御(FTD)和Snort检测引擎的服务器名称识别(SNI)请求过滤漏洞可能允许未经身份验证的远程攻击者绕过受影响设备上的过滤技术,从受影响的主机窃取数据。
英文描述:
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised host. This vulnerability is due to inadequate filtering of the SSL handshake. An attacker could exploit this vulnerability by using data from the SSL client hello packet to communicate with an external server. A successful exploit could allow the attacker to execute a command-and-control attack on a compromised host and perform additional data exfiltration attacks.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Web Security Appliance (WSA) | n/a | - | - |
cpe:2.3:a:cisco:cisco_web_security_appliance_(wsa):n_a:*:*:*:*:*:*:*
|
| cisco | ironport_web_security_appliance | 14.5 | - | - |
cpe:2.3:a:cisco:ironport_web_security_appliance:14.5:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 2.9.18 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:2.9.18:*:*:*:*:*:*:*
|
| cisco | firepower_management_center_virtual_appliance_firmware | 6.6.0 | - | - |
cpe:2.3:o:cisco:firepower_management_center_virtual_appliance_firmware:6.6.0:*:*:*:*:*:*:*
|
| cisco | firepower_management_center_virtual_appliance_firmware | 6.7.0 | - | - |
cpe:2.3:o:cisco:firepower_management_center_virtual_appliance_firmware:6.7.0:*:*:*:*:*:*:*
|
| cisco | firepower_management_center_virtual_appliance_firmware | 7.0.0 | - | - |
cpe:2.3:o:cisco:firepower_management_center_virtual_appliance_firmware:7.0.0:*:*:*:*:*:*:*
|
| cisco | firepower_management_center_virtual_appliance_firmware | 7.1.0 | - | - |
cpe:2.3:o:cisco:firepower_management_center_virtual_appliance_firmware:7.1.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-34749 |
2025-11-11 15:21:00 | 2025-11-11 07:36:55 |
| NVD | nvd_CVE-2021-34749 |
2025-11-11 14:57:41 | 2025-11-11 07:45:13 |
| CNNVD | cnnvd_CNNVD-202108-1648 |
2025-11-11 15:10:42 | 2025-11-11 07:56:51 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信息泄露
- cnnvd_id: 未提取 -> CNNVD-202108-1648
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 7
- data_sources: ['cve'] -> ['cve', 'nvd']