SB2021081903 - Information disclosure in Multiple Cisco Products
Published: August 19, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2021-34749)
The vulnerability allows a remote attacker to exfiltrate data from a compromised host.
The vulnerability exists due to inadequate filtering of the SSL handshake in Server Name Identification (SNI) request filtering. A remote attacker can use data from the SSL client hello packet to communicate with an external server and gain access to sensitive information on the target system.
Remediation
Install update from vendor's website.